Financial monitoring: why a bank asks about a transfer under 400 thousand

The 400,000 UAH figure is a threshold for mandatory financial monitoring only, and it works together with one of the four indicators in Article 20. A suspicious transaction has no threshold at all: the bank looks at the customer profile, not at the amount.

A bank asks about a transfer smaller than 400 thousand because 400,000 UAH is a threshold only for mandatory financial monitoring. And it does not work on its own: the amount has to coincide with one of the four indicators in Article 20 of Law No. 361-IX. A suspicious transaction has no threshold at all. Under Article 21 the bank looks not at the amount but at whether the transaction fits the customer profile, so a request can arrive over five thousand hryvnia.

These are two different mechanisms that everyday speech lumps under one word. Confusing them is the main reason for the surprise: a person read about four hundred thousand and got a request about thirty.

Below: how each procedure works, who takes part in it, what happens step by step after a transaction is suspended, and how suspension differs from an account freeze. We are an exchange service, not lawyers: what follows is what the documents say, without predicting the decision of any particular bank.

Why the bank is obliged to ask rather than choosing to

A source of funds request is not a manager's initiative. A bank is a primary financial monitoring entity: a category defined by Law No. 361-IX, on which the state places the duty to check customers and report transactions to the State Financial Monitoring Service.

finmonitoryng chomu bank pytaie 1 en.svg

Besides banks, the category covers insurers, payment institutions, credit unions, notaries, lawyers in certain transactions, real estate agents, and providers of services related to virtual assets. The list is wider than the banking sector, which is exactly why you can hear a source of funds question outside a bank too.

There is one practical consequence. A bank cannot agree to skip the check as a favour: failing the duty is the bank's own liability before the regulator. So arguing with a manager at a branch is almost always pointless, and a substantive conversation starts with documents.

What amount falls under financial monitoring

The threshold amount for mandatory financial monitoring is 400,000 UAH, Article 20 of Law No. 361-IX. The rule has been in force since 28 April 2020 and had not changed as of August 2026. The amount counts in foreign currency equivalent at the National Bank of Ukraine rate too, so a transfer in dollars is converted into hryvnia at the transaction date.

Now for what most articles in search results leave out. The amount alone does not make a transaction a threshold one. It has to coincide with one of the four indicators in Article 20. No indicator, no mandatory monitoring, however many zeros are involved.

Hence the flip side: an amount below the threshold does not take a transaction out of view. It only takes it out of the mandatory procedure, leaving it in the field of suspicious transactions, where there is no threshold.

Which transactions fall under mandatory financial monitoring

Article 20 lists four indicators, and the amount only works together with them. The first: a party to the transaction is registered in a state that does not follow FATF recommendations. The second: a transaction by a politically exposed person, a family member, or a person associated with them.

The third indicator: a transfer of funds abroad, including to offshore zones on the Cabinet of Ministers list. The fourth: a cash transaction, meaning depositing, transferring or receiving cash.

An ordinary domestic card-to-card transfer between two residents does not fall under Article 20 even for a large amount. That is the answer to the most common misunderstanding: a person moved half a million between their own accounts inside the country and decided the request came because of the threshold, when the grounds were different.

How a suspicious transaction differs from a threshold one

Article 21 contains no figure at all. A five thousand hryvnia transaction can be suspicious if it does not match what the bank knows about the customer. What works here is not arithmetic but comparison: the income declared during KYC, the usual behaviour of the account, the payment descriptions.

A threshold transaction is a formality: the amount and an indicator coincide, the bank reports it. A suspicious one is a judgement. The bank makes it under its own AML procedures, built on the principles set out in National Bank of Ukraine Regulation No. 65 of 19 May 2020.

The difference is tangible for the customer. A threshold transaction is reported, and that is usually the end of it. A suspicious transaction can be suspended, and that is where the story with document requests begins.

Who is subject to financial monitoring

Every customer of a primary monitoring entity is subject to it: individuals, sole proprietors and companies alike. The law has no separate exempt category. The difference is not who gets checked but how closely: the bank assigns the customer a risk level, and the depth of checks follows from it.

The bank determines the risk level itself under internal procedures. It is not a public score, not a regulator's decision and not a record you can see in the app. That is why two banks can behave differently with the same passport and the same turnover.

Virtual assets are mentioned separately among the risk criteria. Which means someone who regularly buys or sells cryptocurrency will most likely not land in the lowest category, not because of any violation but because of the nature of the transactions.

What customer due diligence is

Due diligence is not a one-off act but a continuous process. Its parts: identifying the person when the account is opened, establishing the purpose of the business relationship, establishing the source of funds, and ongoing monitoring of transactions throughout the relationship.

Checking one transaction is just one episode inside that process. The bank looks not at the payment in isolation but at whether it fits the picture assembled earlier. So the same amount passes unnoticed for one customer and triggers a request for another.

There is also enhanced due diligence, for high-risk customers, politically exposed persons and transactions with countries that do not follow FATF recommendations. The depth there is different: the bank establishes not just the source of funds but the source of wealth in general.

The practical conclusion is this. The data you submit when opening an account works for years. A form filled in hastily five years ago remains the benchmark the bank measures today's transactions against.

Financial monitoring of individuals: what it looks like in practice

For an individual, monitoring rarely looks like an inspection. More often it is three things: a form when the account is opened, periodic data updates, and a source of funds request when a transaction does not fit the profile.

The most exposed group is not people transferring large sums but people with many small incoming payments from different senders. That picture matches several risk criteria at once, and it is typical of active P2P.

The practical conclusion for an individual is simple. A profile is built in advance: clear payment descriptions, an up-to-date form, saved proof of income. Once a request has arrived, you cannot change the picture of past months, only explain it.

What happens after a transaction is suspended: step by step

The first step is taken by the bank without notifying the customer in advance: a suspicious transaction is suspended for 2 business days (Article 23). The law provides for no warning before suspension, so people usually find out after the fact, from the app or from support.

The second step is a decision by the State Financial Monitoring Service. It can extend the suspension to 7 business days. The third step comes if the materials are handed to law enforcement: the overall maximum grows to 30 business days.

The fourth step is automatic resumption. If no decision arrives within the allotted period, the transaction resumes on the third business day. In other words, silence from the system works for the customer, not against them.

In parallel comes the fifth step, the one that concerns you directly: a document request from the bank. The law sets no statutory deadline for the customer's reply. We checked both the text of Law No. 361-IX and the banks' own pages: the widely quoted 10 business days is a deadline from one bank's internal procedure, not a legal rule. So the first thing to do on receiving a request is to find the date the bank put in it.

What happens if you fail financial monitoring

If the documents are not provided, the bank does not merely have the option to refuse, it is obliged to. Article 15 is worded as a duty: refuse to carry out the transaction and, where necessary, terminate the business relationship and close the account. The bank reports the refusal to the State Financial Monitoring Service within one business day.

Then there is a consequence that gets mentioned rarely. Banks have the right to share information about people they have refused. Which means a refusal at one bank does not stay that bank's business, and opening an account elsewhere may turn out to be harder.

Until the documents are provided, outgoing transactions on the account may be restricted, which is PUMB's own wording on its own page, not our guess. We will not promise otherwise: the decision in each case is the bank's, and no article guarantees the transaction will go through.

How suspending a transaction differs from freezing an account

These are three different states, and they get confused constantly. Suspending a transaction concerns one payment: it does not go through while the rest of the account works. The periods here are the same 2 / 7 / 30 business days, and automatic resumption applies.

Restricting outgoing transactions is a broader state: the money is on the account and incoming payments arrive, but you cannot spend it until the documents are provided. That is not a sanction but an internal bank measure for the duration of the check.

Closing the account and terminating the relationship is the extreme option from Article 15, reached after a customer refuses to provide documents. Before acting, it is worth establishing exactly which of these states you are in: it determines who to address and whether it makes sense to simply wait the period out.

What a bank has the right to demand and what it does not

A bank has the right to demand documents confirming the source of funds and the substance of the transaction: income certificates, a tax return, contracts, statements, documents on the sale of property or an inheritance. The scope of the request depends on the assigned risk level, so no single list applies to everyone.

What the bank does not have is an official list of documents specifically for income from cryptocurrency. Neither the National Bank of Ukraine nor the Ministry of Finance has published such a list, and the banks' own lists do not include cryptocurrency as a source of income at all. Because of that, a request often looks as though your case has no correct answer.

Lawyers' practice (practice, not a rule) comes down to a chain of three links: the origin of the initial funds, proof of the transactions on the exchange, and the movement of funds there and back. A single exchange statement covers only the middle link. The strongest source document at State Tax Service level is said to be a filed tax return with declared crypto income.

Why different banks ask different questions under the same law

The law sets the duty but not the procedure. It requires assessing risk and checking the source of funds, but which scenarios to use, what thresholds to build into the system and which documents to request is decided by the bank itself in its internal rules.

Hence the discrepancies. One bank asks about an incoming thirty thousand, another says nothing about a hundred. That does not mean one of them is breaking the rule: both meet the same requirement with different tools.

Risk tolerance differs too. A bank that works actively with entrepreneurs is used to mixed incoming payments. A bank whose customers are mostly on salaries sees the same picture as a departure from the norm.

So do not transfer someone else's experience onto your own case. The line about a friend getting it through at this bank says nothing about your profile or your bank's rules.

What happens with repeated triggers

A first document request is an episode. A second and a third within a short period are grounds to revise the customer's risk level. The assessment is not static: it is recalculated when account behaviour departs from the profile systematically.

The effects of a raised level are not felt immediately. Checks get deeper, requests get more frequent, and the range of transactions that pass without questions narrows. The level can be brought back down, but that is slower than raising it.

A separate story is explanations that do not add up. If a person named one source of funds in reply to the first request and another in reply to the second, the discrepancy does more damage than the transaction itself: both answers come into doubt.

How a new customer differs from one with a history

A new customer has no profile to check a transaction against. There is nothing to compare with, so for the first months the bank relies on the form and on the typical behaviour of similar customers. A large incoming payment in the first week after opening an account stands out precisely because there is nothing yet to set it against.

A customer with a history has their own norm. Regular, similar transactions over a year form an expected pattern, and a request comes from a departure from it, not from hitting some amount.

Hence a non-obvious conclusion about switching banks. Moving to a new bank for the sake of calmer transfers wipes out the history you built up: instead of an established profile you become a customer with no past again.

What to do with all this

The most useful action is to check whether what the bank sees matches what you declared about yourself. If the income figure in the form is three years old while the account today lives differently, the discrepancy will turn into a request sooner or later.

The second step is to keep proof before anyone asks for it. Statements, contracts, last year's tax return. Assembling the chain after the fact is harder than building it as you go. A detailed look at the risk criteria themselves is in the article on Ministry of Finance Order No. 465.

And the one limit we are not going around. There is no advice here on avoiding a check or making a transaction inconspicuous, and there will not be: splitting amounts and similar tricks are a risk criterion in their own right, not a way around one.

Author: MW ExchangeUpdated
01

Read next