Limits Management

Limits Management

Every transaction is evaluated through customer segment, risk tier, rail, velocity, platform-wide caps, and fraud screening, in that order, before it’s allowed to proceed.

Limit checkSEPA transfer
SegmentIndividual
Risk tierTier 2
VelocityWithin window
Within limit

Every check, a clear result

Four outcomes, never a silent one

A transaction doesn’t just pass or fail a single test. It moves through several, and whichever one stops it, the customer sees why.

Within limit

Every check clears

Segment, risk tier, rail, velocity and system caps all pass, and the transaction proceeds normally.

Cooldown active

A temporary hold after a sensitive change

Registration, a new beneficiary, a changed password, or a new device can each trigger a short cooldown.

Under review

A person decides

Some tiers, like a newly KYB-verified business, route to manual review rather than an automatic limit.

Blocked

Stopped by a specific check

An unverified account, a velocity breach, or a fraud signal each stop a transaction for a different, identifiable reason.

Every outcome traces back to one specific step in the evaluation order, not a single opaque “limit reached” message.

The evaluation order

Six checks, run in a fixed sequence

Each step narrows what’s actually allowed before the transaction reaches the last one: real-time fraud and AML screening.

  1. 01

    Segment selection

    Individual or corporate decides the base configuration everything else builds on.

  2. 02

    Risk-adjusted calculation

    KYC or KYB tier, account maturity and risk profile scale the limit up or down from there.

  3. 03

    Rail-level amount checks

    Per-transaction, daily, weekly and monthly caps, checked against the specific rail being used.

  4. 04

    Velocity checks

    How many transactions, not just how much, within a given window of time.

  5. 05

    System-wide limits

    Platform-level caps that protect liquidity and infrastructure regardless of any one customer.

  6. 06

    AML and fraud screening

    Real-time compliance and behavioral checks make the final call: approve, hold, or reject.

Risk-adjusted tiers

What’s allowed grows with what’s known

Tier 0

Not verified

View-only. Outgoing activity is blocked until identity is confirmed.

Tier 1

Full KYC, starter wallet

A 24-hour cooldown applies right after verification completes.

Tier 2

Full KYC, standard

Daily and monthly outgoing limits both apply as configured.

Tier 3

Enhanced verification, high-value users

For long-term or high-value customers, verified beyond the standard tier.

A separate track for businesses

Corporate

KYB verified, per profile

A fresh KYB verification carries its own 24-hour cooldown and often starts under manual review.

Two dimensions, everywhere

How much, and how often

Volume limits

Amount-based

Per transaction, daily, weekly and monthly caps on how much can move.

↔
Velocity limits

Count-based

How many transactions happen per minute, hour or day, independent of amount.

Why outgoing is stricter

Incoming and outgoing protect against different things

Outgoing transfers are where fraud actually causes a loss, once money leaves an account it’s hard to recover. Incoming activity carries a different kind of risk: AML exposure and chargebacks, so it’s controlled differently rather than less carefully.

How the two compare

AspectIncomingOutgoing
Main riskAML, chargebacksFraud loss
StrictnessModerateHigh
Cooling periodRareCommon
Beneficiary rulesNoYes
Velocity importanceMediumVery high
Authentication impactLowerHigh
Payment rail limits
Payments
InternalUp to €25,000 / transaction
SEPA / SEPA InstantUp to €15,000 / transaction
SWIFTUp to €50,000 / transaction
FPS (UK) / Canadian localUp to €10,000 equivalent
UAEFTS / IQD domesticUp to €25,000 equivalent
Card Top-UpUp to €2,500 / transaction

Every payment rail

Checked on its own terms, not as one generic transfer

Internal moves, SEPA, SWIFT, local UK, Canadian, UAE and Iraqi rails, and card top-ups, each carry their own per-transaction, daily, weekly and monthly limits.

  • Incoming and outgoing tracked separatelyDifferent risk, different limits, same rail.
  • Instant rails handled on their own termsSEPA Instant doesn’t have to mirror standard SEPA.
  • Set per tenant, not fixed platform-wideEach business configures values to fit its own risk appetite.

Crypto and FX

The same model, extended, not bolted on

Crypto direction and FX conversions follow the same volume-and-velocity structure as fiat payments, with one extra rule for FX: the cap applies to total converted volume, not each conversion separately.

  • Every crypto direction, its own limitCrypto-to-crypto, fiat-to-crypto, deposits and withdrawals.
  • Chained FX conversions still count onceEUR to USD to GBP to EUR all counts toward the same daily cap.
  • Rapid pair-switching is its own signalFlagged by velocity controls, separately from volume.
Crypto & FX limits
Crypto & FX
Crypto2CryptoConfigurable
Fiat2Crypto / Crypto2FiatConfigurable
Crypto Deposit / WithdrawalConfigurable
FX conversion (total volume)Configurable

A safeguard after sensitive changes

What triggers a cooldown period

Right after registration, adding a new beneficiary, changing an email, phone number or password, or logging in from a new device for the first time, outgoing activity is held back briefly before resuming normally.

Related FinHost modules

Part of the same account and compliance experience

Get started

Set limits that reflect who’s actually transacting

Six checks, run in order, on every transaction, with a specific reason whenever one of them stops it.

ResultWithin limit
SegmentIndividual
RailSEPA

Frequently Asked Questions

What determines which limits apply to a transaction?
A six-step check: customer segment, a risk-adjusted tier, rail-level amount limits, velocity limits, system-wide caps, and finally AML and fraud screening. Any one of them can stop or hold a transaction.
Why are outgoing limits stricter than incoming ones?
Because outgoing transfers are where fraud actually causes a loss, once money leaves an account, it’s difficult to recover. Incoming activity carries different risks, mainly AML and chargeback exposure, so it’s controlled differently rather than less carefully.
What happens right after a customer changes their password or adds a new beneficiary?
A cooldown period applies. The same applies right after registration, a beneficiary addition, an email, phone or password change, or a first login from a new device.
How is a daily outgoing limit actually calculated?
As the sum of all outgoing transaction amounts for that day, including card and crypto withdrawals, not just bank transfers. The monthly figure works the same way, summed over the calendar month.
Do individual and business customers follow the same rules?
The same underlying logic applies to both, but the values differ, and the risk-tier structure itself is different: business limits are typically confirmed through KYB verification and can involve manual review rather than a fixed self-serve tier.
Can someone bypass an FX limit by converting through multiple currency pairs?
No. FX limits apply across total converted volume, so a sequence like EUR to USD, then USD to GBP, then GBP to EUR all counts toward the same cap rather than resetting with each conversion.
What’s the difference between a volume limit and a velocity limit?
A volume limit caps how much moves, in a single transaction or over a day, week or month. A velocity limit caps how many transactions happen, within a minute, an hour or a day, regardless of amount.