The Wolfsberg Group’s new guidance on banking services for non-bank payment service providers addresses a structural weakness in the payment system: banks provide the accounts through which payment institutions collect, pool and redistribute money, while often seeing only part of the underlying payment chain.
Wolfsberg does not treat this limited visibility as an excuse. It treats it as a financial-crime risk that the bank must understand and control.
The guidance is therefore directly relevant to ING Bank N.V. and the payment infrastructure used by Payvision B.V. for the online trading platforms associated with Gal Barak and Uwe Lenhoff.
Between 2015 and early 2019, Payvision processed more than EUR 130 million in card payments for platforms later classified by German and Austrian criminal authorities as parts of large-scale fraud schemes. Those schemes affected more than 60,000 consumers and caused losses of approximately EUR 340 million.
The key question is not whether ING knew every individual cardholder. It is whether ING adequately understood the merchant-acquiring business, customer portfolio and risks behind the pooled Payvision accounts—and whether it acted when those risks intensified.
The bank behind the payment institution
The Wolfsberg guidance is directed at financial institutions providing banking services to non-bank PSPs, including payment institutions, electronic-money institutions and third-party payment processors. These PSPs depend on banks for accounts, payment-system access and settlement infrastructure, while the resulting layers between originator and beneficiary reduce transparency and complicate monitoring.
Wolfsberg identifies three governing principles: a risk-based approach, payment transparency and comprehensive risk management. In particular, the bank must thoroughly understand the PSP’s business model, its customer activities and the financial-crime controls on which the bank may need to rely.
This moves the inquiry beyond formal corporate KYC. It is not enough to identify the PSP, its directors and beneficial owners. The bank must understand what the PSP actually does through the account.
That distinction is central to the ING-Payvision relationship.
ING acquired 75% of Payvision in the first quarter of 2018 and later became its sole owner. But its connection to the payment infrastructure began earlier. The available records show that ING had provided payment, trust or financing facilities to Payvision and the Stichting Trusted Third Party Payvision, or STTP, since at least 2015 or 2016. A Dutch judgment from March 2016 already documented ING within the Payvision/STTP account structure.
ING therefore occupied two separate positions: first as account bank and, from 2018 onward, additionally as controlling shareholder. The first role existed independently of the acquisition and carried its own KYC and monitoring obligations.
Wolfsberg’s crucial distinction: whose money is moving?
One of the strongest parts of the new guidance is its distinction between proprietary payments and third-party payment flows.
Proprietary flows involve the PSP’s own operating expenses, such as salaries or rent. They are generally less risky because the bank is not directly exposed to the PSP’s underlying customers.
The position changes where the PSP uses its account to make or receive payments on behalf of those customers. Wolfsberg states that such third-party flows may expose the bank to the PSP’s underlying customer base in a manner comparable to correspondent banking. Understanding the PSP’s customer portfolio is therefore described as crucial.
The Payvision Stichting accounts were plainly not ordinary operating accounts. They formed part of a merchant-acquiring and settlement structure through which consumer card payments were collected, pooled and distributed.
Wolfsberg expressly includes merchant acquiring within its framework: funds are collected from retail customers, businesses or marketplaces and settled to merchants or suppliers through collection and settlement accounts provided by banks.
That description closely matches the documented Payvision model.
Why pooled payments require deeper scrutiny
Wolfsberg pays particular attention to bundled, netted and bulk payment flows.
Merchant servicing is identified as a many-to-one structure. More complex many-to-many arrangements arise when payments from several originators are aggregated and later distributed to multiple beneficiaries. Wolfsberg considers these models higher risk because aggregation reduces transparency and makes suspicious-activity screening and monitoring more difficult.
The consequence is important. Where the bank cannot directly see every underlying transaction, it becomes more dependent on the PSP’s own controls. But Wolfsberg does not endorse blind reliance. The bank must understand the PSP’s risk-management framework and be able to take reasonable comfort from its quality and effectiveness.
Applied to ING, this produces the central test:
What did ING do to establish that Payvision’s merchant onboarding, beneficial-owner checks, fraud controls, transaction monitoring and escalation procedures were capable of managing the risks passing through the pooled accounts?
The answer cannot be that Payvision was regulated. Licensing is only one element of the Wolfsberg assessment.
Assessing the PSP’s licence — and its merchant controls
Wolfsberg requires the bank to document the PSP’s licensing status and assess whether that licence aligns with its business model and the activities supported by the bank. This concerns Payvision’s own licence, not a direct obligation on ING to verify every regulatory licence held by every underlying merchant.
The merchant issue arises at a different level of the Wolfsberg framework. In a merchant-acquiring relationship, the bank must understand the PSP’s underlying customer portfolio and assess the effectiveness of its customer due-diligence and high-risk customer controls. This includes how the PSP identifies merchants and beneficial owners, assigns risk ratings, applies enhanced due diligence and responds to licensing or regulatory concerns.
The relevant question for ING is therefore not simply whether Payvision held a Dutch payment-institution licence. It is whether ING adequately assessed Payvision’s ability to control the high-risk merchants processed through the banking relationship.
The criminal-file evidence shows that Payvision repeatedly raised questions about the absence of MiFID authorisations for merchants connected with the Barak and Lenhoff platforms. Processing nevertheless continued through changing merchant and MID structures. These facts do not establish that ING itself was required to verify each merchant’s MiFID licence. They do raise the question whether Payvision’s merchant due-diligence controls were effective and whether ING could reasonably continue to rely on them.
Controlled reliance, not blind delegation
Wolfsberg recommends that traditional due diligence be supplemented by PSP-specific measures. Banks should use tailored assessments covering the business model, funds flows, payment corridors and financial-crime controls. They must also place substantial weight on ongoing due diligence, including event-driven reassessments following negative news, ownership changes, financial-crime incidents, licensing changes or the introduction of new payment flows and intermediaries.
The guidance is unusually specific about the PSP controls the bank should assess, including governance, compliance resources, customer and beneficial-owner due diligence, high-risk customer reviews, transaction and fraud monitoring, alert backlogs and remediation.
This is the opposite of outsourcing responsibility.
The bank may rely on the PSP for some underlying data and controls. But that reliance must be assessed, documented and continuously tested against the actual account activity.
That is especially relevant where the PSP’s portfolio grows rapidly, contains high-risk merchants or generates persistent fraud and chargeback signals.
The Payvision risk profile was not static
According to Payvision founder Rudolf Booker’s own statements, Payvision processed approximately EUR 77.7 million for the Barak platforms and EUR 55.6 million for the Lenhoff platforms. The records also document thousands of chargeback requests and fraud reports, as well as 273 suspicious-activity reports filed with the Dutch FIU in connection with the relevant merchant structures.
The account activity involved mass consumer payments from more than 30 countries, online financial products, high-risk card-not-present processing, merchant and MID changes, rolling reserves, withdrawals, changing payout channels and, in some cases, payments to recipients other than the formal merchants.
One documented example is the transfer of approximately EUR 3.1 million between February and April 2018 from the STTP account at ING to Winslet Enterprises EOOD in Bulgaria. Winslet was controlled by Uwe Lenhoff but was not the formal Payvision merchant Hithcliff Ltd. This was one additional indicator that the economic reality of the payment flows could not be understood merely from the name of the contractual merchant.
Third-party settlements are not automatically unlawful. They are nevertheless relevant where changes in recipients, payout structures or intermediaries alter the bank’s exposure or reveal a divergence between the formal merchant and the economic beneficiary.
Fraud is not separate from AML risk
A particularly important feature of the new guidance is its express treatment of fraud.
Wolfsberg warns that fragmented oversight within PSP structures can weaken fraud detection and escalation, allowing fraudulent activity to continue longer than it might in a traditional banking relationship. It therefore expects banks to assess the PSP’s fraud-detection, alert-management and escalation systems.
This is directly relevant to Payvision.
The documented signals included excessive chargeback ratios, thousands of fraud reports, card-scheme penalties, consumer complaints, public regulatory warnings, merchant restructuring and repeated licensing concerns. Payvision’s own compliance department reportedly raised serious objections to Gpay Ltd in early 2018 because of insufficient transparency. Nevertheless, the relationship continued and a new agreement was concluded in July 2018 under which Payvision charged a processing fee of 7%.
Payvision did not merely observe those risk levels; it monetised them through chargeback and fraud-risk premiums. A March 2018 charge imposed on Hithcliff amounted to approximately EUR 658,000.
The question for ING is not whether any one of these indicators automatically required termination. It is whether the monitoring framework connected them and reassessed the relationship as the cumulative risk intensified.
Risk appetite must be aligned
Wolfsberg also addresses a point of particular relevance to ING: the alignment between the PSP’s customer risk appetite and that of the bank.
The bank should assess whether the PSP has robust controls for the types of customers it accepts. If the PSP’s risk appetite does not align with the bank’s, the parties should determine which payment flows the bank will and will not support.
ING later acknowledged publicly that parts of Payvision’s customer portfolio did not fit ING’s desired risk profile.
That makes timing decisive.
When did ING identify the mismatch? Did it arise only after the acquisition, or was it already evident from ING’s earlier account relationship? Which merchant sectors and payment flows were restricted? How quickly were the identified risks addressed?
The fact that ING eventually concluded that parts of the portfolio were unsuitable does not answer whether the existing controls reacted in time.
Wolfsberg 2026 does not create the earlier duties
The Wolfsberg guidance is not binding legislation, and it should not be presented as retroactively determining ING’s legal obligations between 2015 and 2019.
It translates longstanding risk-based KYC and monitoring principles into the specific context of non-bank PSP banking.
The Fourth Anti-Money Laundering Directive already required obliged institutions to identify their customers and beneficial owners, understand the purpose and intended nature of the relationship and monitor transactions throughout that relationship for consistency with their knowledge of the customer, its business and risk profile.
Wolfsberg now explains what those principles mean when the customer is a PSP moving pooled third-party funds: traditional KYC must be supplemented by an understanding of the underlying customer portfolio, payment flows, corridors and control environment.
The guidance does not invent the duty to understand the customer’s business. It exposes how inadequate a purely formal understanding would be in a pooled-account structure.
This chronology is particularly striking because ING itself was already under criminal investigation for serious and structural AML failures while it was acquiring Booker’s shares in Payvision and while providing account infrastructure to Payvision and STTP in 2018. On 4 September 2018, ING agreed to pay EUR 775 million — EUR 675 million as a fine and EUR 100 million in disgorgement — after the Dutch Public Prosecution Service found systemic deficiencies in customer due diligence, risk classification, transaction monitoring and the termination of high-risk relationships. At the time, it was the largest criminal settlement in Dutch history and one of Europe’s most significant AML enforcement actions. The relevant question is therefore unavoidable: while ING was being investigated for failing to understand and monitor the risks within its own customer base, how effectively was it monitoring the pooled third-party payment flows passing through the Payvision infrastructure?
Did ING care at all?
It would be legally inaccurate to argue that ING had to perform full KYC on every consumer who paid through Payvision.
The correct question is whether ING understood the categories of merchants, products, jurisdictions and payment flows introduced through Payvision, whether it adequately assessed Payvision’s controls and whether it reacted when the actual activity diverged from the expected profile.
The new Wolfsberg guidance makes one point unmistakable:
Reduced visibility into pooled PSP payments increases the need for deeper due diligence. It does not reduce it.
The available evidence does not establish what every ING employee knew at every stage. It does establish that ING provided banking infrastructure within a payment structure used to pool and distribute substantial consumer funds connected with the Barak and Lenhoff fraud platforms.
The unresolved question is therefore not whether ING knew every victim.
It is whether ING understood the risks behind the Payvision pool—and what it did when those risks became increasingly visible.




