Skip to main content Skip to navigation

How e-money issuer MCash applies risk appetite in practice

In light of Bank Negara Malaysia (BNM)’s recent, stricter enforcement posture and the scam crisis that cost the country RM2.97 billion in 2025 alone, one reasonable conversation Malaysian compliance leaders should have is around navigating the regulatory landscape and the future of compliance programs. 

At our AML Unplugged Malaysia event in July 2026, our Global Head of FCC Strategy, Andrew Davies, sat down with Farid Jalil, Head of Compliance at MCash, an e-money issuer licensed by BNM. 

Together, they discussed what risk-based compliance looks like from a payments firm perspective, especially when the customer base is, by design, underserved.

Compliance calibrated to who you serve

Known as one of Malaysia’s pioneering FinTech companies, e-money issuer MCash participated in the DuitNow QR code initiative that fosters inclusive digital payments. 

Having recently partnered with a third-party remittance provider for that specific rail, the firm’s compliance philosophy is built around risk appetite rather than risk elimination. This is particularly suited to customers who often cannot produce the documentation that more traditional institutions require. 

“We are not trying to eliminate the risk. What we are doing right now is we are calibrating the risk into the risk appetite. In a way, we are honest about who we serve.”

– Farid Jalil, Head of Compliance, MCash

Currently, in its customer onboarding, MCash aims to address three common limitations: 

  • The quality of a customer’s source of funds (SOF).
  • The identification documents that customers can realistically produce.
  • Onboarding speed, which is key to customer satisfaction. 

Thanks to automation, the firm has cut the onboarding process time to three to four minutes.

Once a customer is onboarded, a separate two-layer model handles ongoing transaction monitoring at volume: automated rules process velocity and transaction volume in real time, with analysts reviewing the alerts those rules generate as a second layer.  

Fraud and AML (FRAML) as a shared responsibility

The RM2.97 billion lost to fraud in Malaysia should prompt any e-money compliance team to determine whose problem this is and who should catch it. 

“Because we’ve had this idea in the industry of fraud and anti-money laundering (AML), we call it FRAML. But if you think about human trafficking, drug trafficking, illegal arms trading, that’s beyond fraud and AML. So I now have this notion of beyond FRAML, and this is where hopefully these models will be effective.”

– Andrew Davies, Global Head of FCC Strategy, ComplyAdvantage

A significant share of fraud cases involves customers authorizing transactions themselves after being deceived by increasingly sophisticated threat actors, such as scammers posing as government officials offering grants. The industry generally refers to this pattern as authorized push payment (APP) fraud – the customer initiates and approves the transfer, having been manipulated into doing so – though on the ground, compliance teams sometimes use looser terms for the same problem. 

Responsibility, in this framing, is spread between the user, the e-money issuer, and other parties in the ecosystem, with education and product-level controls as the two levers a compliance team controls directly. The two national fraud-dedicated frameworks and hotlines – Malaysia’s National Fraud Portal (NFP) and National Scam Response Centre (NSRC) – also provide victims with the support they need to resolve cases once they occur. 

“Most of the scams that we are seeing, the user actually authorizes the transaction. I’m pretty sure everyone in this room can vouch for that. […] I want to prevent financial crime. I just want to be part of a larger group working to prevent it – because financial crime affects others. It funds illegal gambling, prostitution, human trafficking, and wildlife trafficking. I want to play my small part in that, and contribute to a larger context.”

– Farid Jalil, Head of Compliance, MCash

To help fight financial crime in its many forms, at MCash, fraud and compliance sit as deliberately separate functions, preserving compliance’s independent oversight role. 

Detection is outpacing recovery

Malaysia’s NFP has cut fund-tracing time from days to 30 minutes – a real gain, but one that surfaces a different problem underneath it: knowing where stolen funds went, and getting them back, are not the same capability.

“We can confirm the money is gone, we know where it went, and we can tell the customer what happened. But the speed of detection has not yet translated to the speed of recovery. We know where the money is going, but we cannot recover it.”

– Farid Jalil, Head of Compliance, MCash

That gap is part of why a centralized, shared fraud infrastructure across a payment network – rather than each institution running its own defenses in isolation – is increasingly discussed as the more effective long-term model. 

“I worked with the Reserve Bank of Australia (RBA) on a fraud overlay service […] they were calling it the New Payments Platform (NPP) at the time. […] a centralized service […] would help detect fraud before it happens […] Like a centralized service so that anyone who’s within the payment infrastructure can share more information and lead a detection approach before it happens.”

– Andrew Davies, Global Head of FCC Strategy, ComplyAdvantage

In Malaysia’s case, that infrastructure already exists in an early form: MCash points to the NFP itself, connecting participants like e-money issuers and banks, as a step toward exactly that kind of shared visibility.

“[In Malaysia] we already have the NFP protocol.[…] We are able to […] fund tracing, and from there, we are able to check everything. So in a way, the communication is already centralized.”

– Farid Jalil, Head of Compliance, MCash

Alert fatigue

Yet in practice, detection and reporting are two different things. The gap between them lies less in the technology itself than in what happens to an alert after it fires. Teams that repeatedly see the same flags every day eventually can easily overlook them, hence the importance of judgment calls. 

“I think you get desensitized. The system is able to generate a lot of alerts, but then what do you do after that? We should be filing it by default, but then we think about it first – should we file for it or should we not file for it? I would say it’s the resourcing, and also the process.”

– Farid Jalil, Head of Compliance, MCash

This pattern is common across the financial crime industry. Legacy technology generates more investigations than analysts can realistically review, and skilled, experienced financial crime fighters end up spending their time clearing a queue rather than investigating the cases that matter most.  

“The technology just creates too many investigations, too many cases, and the analysts just get fatigued with looking at it. An analyst who wants to come in and do a good job and fight financial crime becomes overwhelmed with alerts and cases – rather than a superhero financial crime fighter, they just become someone who’s there to clear an alert.”

– Andrew Davies, Global Head of FCC Strategy, ComplyAdvantage

Risk scoring without a uniform rule

Applying consistent standards to a customer base that, by design, doesn’t fit the profile those standards were built around is a challenge for many firms. For customers with irregular income, a solution is to anchor detection to each customer’s own transaction history rather than a fixed population-wide threshold. 

“Instead of anchoring that as a trigger, we anchor that behavior into the transaction history. We just check their behavior and compare that against their own, instead of putting a uniform rule.”

– Farid Jalil, Head of Compliance, MCash

The same principle applies to enhanced due diligence (EDD). Rather than the ownership-structure and beneficial-ownership checks built for complex corporate customers, EDD gets calibrated to what the customer base can realistically produce, i.e., accepting Malaysia’s national identification document alongside a passport where needed. 

“It has to be based on the risk that we are willing to take. It cannot be the complex corporate [standard] that we need to apply to them.”

– Farid Jalil, Head of Compliance, MCash

Aligning compliance calibration with underserved populations

To summarize, here are three practical, actionable takeaways for compliance leaders operating in high-growth, financially underserved markets:

  • Build risk appetite into onboarding from day one: Identity and source-of-funds checks reflect what your actual customer base can produce, not a standard built for a different population.
  • Treat alert volume as a resourcing and process problem before a technology problem: Use statistically valid segmentation to route analyst attention toward alerts that matter.
  • Consider shared, centralized fraud infrastructure: Faster fraud detection doesn’t guarantee faster fund recovery, so cross-institution collaboration matters as much as internal controls.

Transform your AML compliance with AI-native solutions

A cloud-based compliance platform, ComplyAdvantage Mesh combines AML risk intelligence with actionable risk signals to screen customers and monitor their behavior in near real-time.

Get a demo

Originally published 28 July 2026, updated 28 July 2026

Disclaimer: This is for general information only. The information presented does not constitute legal advice. ComplyAdvantage accepts no responsibility for any information contained herein and disclaims and excludes any liability in respect of the contents or for action taken based on this information.

Copyright © 2026 IVXS UK Limited (trading as ComplyAdvantage).