Danish FSA reports results of inspection of Inpay A/S
Denmark’s Financial Supervisory Authority (FSA) today announced the results of its inspection of Inpay A/S conducted in March 2026.
The inspection was an investigation of the company’s compliance with selected areas of the Payments Act and the Money Laundering Act, with a particular focus on the company’s high-risk customers, such as business customers within online gaming. The inspection also included the company’s compliance with EU sanctions.
Inpay A/S is a Danish e-money institution with its headquarters in Copenhagen. The company was established in 2013 and has since had its licenses extended to include more payment and e-money services.
Inpay’s business customers mainly consist of companies within online gaming and financial services. The online gaming providers either have their own gaming license (iGaming customers) or facilitate payments for gaming providers. Inpay’s private customers are exclusively end users of the iGaming customers.
The company’s business model primarily consists of facilitating cross-border payments for business customers. This typically happens when a payer makes a payment to Inpay’s account, after which the payee or a payment institution, typically in another country, is notified. The amount is then paid out from Inpay’s or the payment institution’s account in the recipient country in the agreed currency. Inpay facilitates the payment chain using a large network of correspondent connections, including respondents outside the EU.
The company operates an online platform and, through external partners, also offers virtual IBANs and payments with crypto assets to iGaming customers.
The regulator concluded, based on the inspection, that there are a number of areas that give rise to supervisory reactions.
The company has not secured sufficient resources to support sound operations and compliance with applicable requirements, including sufficient internal control procedures in the outsourcing and money laundering areas. It continuously assumes new risks without the governance structure and controls being sufficiently adapted to the company’s operations and risk profile.
This entails a risk that significant risks are not identified or handled in a timely manner, and that the company cannot effectively prevent money laundering and terrorist financing or ensure sound operations.
The company has therefore been ordered to ensure that there are sufficient resources to support a sound provision of services, and that the resources are used to a sufficient extent to comply with all applicable requirements and for the benefit of the company’s customers, including to ensure sufficient internal control procedures in the outsourcing area as well as sufficient business procedures and controls for the alarm handling in the money laundering area, so that employees cannot abuse their position when carrying out investigations pursuant to Section 25 of the Money Laundering Act.
The company’s business procedure for customer due diligence procedures is not sufficiently operational. The company is therefore not able to sufficiently assess the purpose and intended nature of business relationships, including for payment agents, gaming companies and customers with complex ownership structures. The company is also unable to react if a gaming company has its license to offer games withdrawn, and has not established a sufficiently systematic transaction monitoring of customers’ expected activities within the SEPA payment area.
The deficiencies entail a significant risk that the company cannot sufficiently document that it does not facilitate payments for gaming companies without the necessary permission in the relevant countries and the provision of payment services without permission, which entails a high risk of money laundering and terrorist financing. At the same time, the company risks lacking the necessary information to effectively monitor customer relationships, detect suspicious transactions and timely notify the Danish Anti-Money Laundering Secretariat.
The company has therefore been ordered to ensure that its business process for customer due diligence procedures is sufficiently operational, that the company sufficiently assesses the purpose and intended nature of the business relationship, that customer due diligence procedures are carried out when a customer’s relevant circumstances change, and that information about customers’ expected transactions is included in the monitoring system.
The company has not ensured a clear and consistent division of responsibilities in the organization and has not implemented effective procedures to prevent conflicts of interest, especially in relation to management and ownership.
This entails a risk that management cannot act independently and that decisions are made without sufficient control, which may weaken the company’s governance and increase the risk of inappropriate operation.
The company has therefore been ordered to ensure a clear organizational structure with a well-defined, transparent and consistent wait division of responsibilities, including ensuring that management can act independently of the company’s ultimate owner, and that effective procedures have been implemented for the purpose of handling and preventing conflicts of interest.
Also, the FSA found that the company’s enhanced customer due diligence procedures for respondent connections outside the EU are not sufficient. The company cannot document that it has assessed the quality of supervision of the respondent in the country of registration, and has not ensured that it does not enter into or maintain a correspondent relationship with an empty banking company.
The deficiencies entail a risk that the company cooperates with respondents who are subject to insufficient supervision, or who are neither physically present in the country of registration nor affiliated with a company subject to effective consolidated supervision. The company thus risks not being able to effectively limit the risk of money laundering and terrorist financing.
The company has therefore been ordered to obtain sufficient information on respondent connections outside the EU in order to validate the quality of supervision of the respondent and to be able to document this to the Danish Financial Supervisory Authority. The company must also ensure that it does not enter into or maintain a correspondent relationship with a so-called shell bank.
Based on the same inspection, the Danish Financial Supervisory Authority has made a separate decision that Inpay must temporarily stop establishing new business customer relationships within online gaming. The decision was made pursuant to Section 51 b of the Money Laundering Act.
