DPO Radio

Vietnam’s active payment stack combines the Anti-Money Laundering Law and Decree 19 with Decree 52 on non-cash payments and State Bank circulars governing payment accounts and bank cards.
This is an optional payments-sector overlay for banks, fintechs, payment intermediaries, e-wallet providers, account providers, card issuers, and acquirers. It extends beyond the Banking Circular 83 internal-controls overlay rather than replacing it.
Direct use requires confirmed payment-sector scope. Other organizations, including payment-heavy customers that need visibility into provider expectations, can install it for reference.
Vietnam Anti-Money Laundering Law 2022 and Decree 19/2023, Decree 52/2024 on Non-Cash Payments, and State Bank Circulars 17/2024 (payment accounts) and 18/2024 (bank cards), extending beyond the Banking Circular 83 internal-controls overlay.
Banks, fintechs, intermediaries, e-wallets, payment accounts, card issuers, and acquirers.
Customer identity, beneficial ownership, risk, monitoring, and reporting evidence.
eKYC, biometrics, verification, matching, exceptions, access, and retention.
Services, wallets, merchants, transactions, devices, authentication, security, fraud, and incidents.
Applicable artifact, trigger, responsible party, verified channel, and acknowledgement.
Optional; direct after payments-scope confirmation, or reference-only.

Teams can inventory payment services and connect accounts, wallets, cards, merchants, devices, channels, and systems. AML evidence remains linked to customer and transaction records without replacing specialist review.
eKYC and biometric records capture verification, exceptions, access, retention, and privacy context. Card-data workflows connect safeguards, fraud events, incidents, vendors, remediation, and closure.
Maps accounts, wallets, cards, customers, devices, transactions, and biometrics.
Explore Data MappingSupports payment, identity, card, and technology-provider oversight.
Explore Vendor GovernanceCoordinates due diligence, review, incident, remediation, and response work.
Explore Task ManagementPreserves identity, transaction, security, approval, and incident history.
Explore Audit Trail


This overlay shares its evidence structures and workflow engine with the Banking Circular 83 internal-controls overlay, so a bank already tracking internal controls extends into AML, eKYC, and card evidence without standing up a second system.

Identity verification, transaction monitoring, and card-security incidents stay linked end to end, so a fraud event, the remediation it triggered, and the vendor involved sit on one connected record instead of three separate files.

Organizations that rely on payment providers but are not themselves regulated can install the overlay in reference-only mode, giving vendor-management teams visibility into provider expectations without activating obligations that are not theirs.
See how ComplianceOne connects payment services, AML, identity, cards, transactions, security, and evidence.

No. It adds AML, non-cash payment, account, identity, biometric, and card evidence beyond Circular 83’s internal-control scope.
Direct mode is intended for confirmed banks, fintechs, payment intermediaries, e-wallet providers, account providers, card issuers, and acquirers.
They can use reference-only mode to understand and organize provider-related evidence without activating direct sector obligations.
No unverified reporting form is included. Teams should use the current artifact and channel confirmed for their role and circumstance.
Yes. Identity, biometric, device, transaction, access, retention, and security records can connect to applicable privacy and data-governance evidence.

Test payment inventory, eKYC, biometric, card, transaction, and incident evidence.

Review regulated roles, payment services, data flows, controls, and evidence ownership.