MAINNET· live since 2020BLOCK #33,888,018FINALITY 8.00sOPS / BLOCK 0VALIDATORS 11 · 5 ORGSTOTAL XBN 369B XBNCIRCULATING 74.10B XBNHFBA CONSENSUS · 3–5s FINALITYMAINNET· live since 2020BLOCK #33,888,018FINALITY 8.00sOPS / BLOCK 0VALIDATORS 11 · 5 ORGSTOTAL XBN 369B XBNCIRCULATING 74.10B XBNHFBA CONSENSUS · 3–5s FINALITY
Bantu
Contents03 · AML, audit & supervision

Enforcement hooks, not a compliance vendor.

Bantu provides enforcement hooks. It does not independently conduct KYC, sanctions screening, transaction monitoring or regulatory reporting. Those functions remain with the central banks, commercial banks, licensed fintechs, payment service providers, stablecoin issuers, anchors, regulated custodians and compliance providers operating on the network. This chapter documents exactly where the line falls.

Edition 1Last reviewed July 2026bantufoundation.org/institutions
Operating model

Five steps, two domains.#

The Bantu compliance architecture places identity and screening off-chain, inside the institution's regulated perimeter, and enforcement on-chain where it is deterministic and evidenced. AML and KYC are an off-chain attestation and integration layer; the ledger provides the immutable transaction trail beneath it.

Figure 7 · Compliance operating model
  1. 01
    Screen

    The institution performs KYC, KYB, sanctions, PEP and adverse-media screening under its own licence and policy.

    Off-chain
  2. 02
    Map

    The institution maps an approved customer or entity to an approved Bantu account.

    Off-chain
  3. 03
    Authorise

    The issuer authorises the customer's trustline where a permissioned asset is in use.

    On-chain
  4. 04
    Monitor

    The institution monitors activity through Bantu ledger events, internal analytics and its own compliance systems.

    On-chain
  5. 05
    Escalate

    Suspicious or prohibited activity triggers off-chain investigation and, where legally appropriate, a freeze, authorization revocation or clawback action.

    On-chain
The ledger never holds KYC files, identity documents, sanctions records or customer information. It holds the account references and the transaction history that make enforcement evidenced.
Audit trail

Real-time, permanent, and not privileged.#

The Expansion API exposes finalised ledgers, transactions, operations, effects, account state, balances, signers, trustlines, assets, order books and trades. That makes it possible to build real-time audit, reconciliation, supervisory and transaction-monitoring systems around the ledger rather than around a vendor's reporting export.

  • Asset issuance — attributable and timestamped
  • Transfer of any asset — sender, recipient, amount, memo
  • Account authorisation events — granted or revoked
  • Trustline creation — every opt-in to hold an issued asset
  • Freeze and unfreeze — named operations on the ledger
  • Clawback — with full on-chain provenance
  • Path payments and swaps — multi-hop conversions
  • Signer and threshold changes — every custody change
Supervision

A regulator can run its own read infrastructure.#

Supervisory visibility on Bantu does not depend on a reporting relationship with the issuer. A regulator or central bank can operate independent read infrastructure against the ledger and monitor the following continuously.

Figure 8 · Supervisory read model
Monetary
Currency supply
Monetary
Issuer balances
Flow
Distribution-account movements
Access
Trustline approvals and revocations
Flow
Treasury transfers
Flow
Cross-border settlement flows
Market
Liquidity positions
Market
FX conversion paths
Risk
Institutional exposure
Risk
Exceptional interventions
Risk
Operational anomalies
No privileged access to any institution's internal systems is required to observe any of these. The supervisor's view is derived from the same ledger the participants settle on.
Data protection

The proof is public. The information is not.

Personal information should remain off-chain. The public or shared ledger holds cryptographic account references and transaction information, while KYC files, identity documents, sanctions records and customer information stay inside the institution's controlled systems. This is a design constraint of any compliant deployment, not an optional posture.

Never placed on the ledger
  • Customer and guest names
  • Contact details
  • Passport and identity information
  • Bank account details and payment credentials
  • Payment instructions and receipt images
  • KYC files and sanctions records
  • Private financial information
Chapter 04

From controls to institutions.

Chapters 01 to 03 document the mechanisms. Chapter 04 sets them against what commercial banks, central banks and cross-border settlement networks actually require.