| European Union | Directive (EU) 2015/2366 (PSD2) and its regulatory technical standards on strong customer authentication · Regulation (EU) 2024/1624 on anti money laundering · Regulation (EU) 2022/2554 (DORA) · Regulation (EU) 2024/1689 (AI Act) | Payments must be authenticated and attributable to the payer. Transaction records must be retained for five years. ICT systems must log activity so that incidents can be detected and investigated. High risk AI systems must log events automatically. | Mandates, intents, decisions and receipts are fixed in a sequence that can be demonstrated, and every record is attributable to a signing account. |
| United Kingdom | Payment Services Regulations 2017 · Money Laundering Regulations 2017 · FCA Handbook SYSC 9 | Payment transactions must be authorised by the payer. Customer due diligence and transaction records must be kept for five years. Firms must keep orderly records sufficient for supervision. | Tamper evident proof of authority and execution for every agent payment, kept for the full retention period. |
| United States | Electronic Fund Transfer Act and Regulation E · Bank Secrecy Act record keeping · OFAC sanctions record keeping · 23 NYCRR 500 | Consumers have error resolution rights for unauthorised transfers. Transaction records must be retained for five years under the Bank Secrecy Act and for ten years under OFAC rules. Covered entities must maintain audit trails capable of reconstructing material financial transactions. | A reconstructable trail from mandate to settlement, signed with post quantum cryptography and verifiable for ten years and beyond. |
| Japan | Payment Services Act · Act on Prevention of Transfer of Criminal Proceeds | Payment service providers must manage the security of their systems. Verification and transaction records must be retained for seven years. | Integrity and time evidence for each payment record that remains valid for the full retention period. |
| South Korea | Electronic Financial Transactions Act · Act on Reporting and Using Specified Financial Transaction Information | Electronic financial transaction records must be kept, generally for five years, and protected against forgery and alteration. Financial institutions bear liability for unauthorised transactions. | Tamper evident payment records that the Financial Supervisory Service or a court can verify independently. |
| Singapore | Payment Services Act 2019 · MAS Technology Risk Management Guidelines · MAS AML notices | Payment institutions must maintain audit trails and protect system integrity. Transaction records must be kept for five years. | Independent evidence of each agent payment, anchored outside the systems of the institution that made it. |
| Hong Kong | Payment Systems and Stored Value Facilities Ordinance (Cap. 584) · Anti Money Laundering and Counter Terrorist Financing Ordinance (Cap. 615) · Stablecoins Ordinance (Cap. 656) | Stored value facility licensees and licensed stablecoin issuers operate under HKMA supervision with sound risk management and system integrity. Customer due diligence and transaction records must be kept for at least five years and be sufficient to reconstruct each transaction. | Fixed fingerprints of every payment record, from which each transaction can be reconstructed and verified for the full retention period. |