AML & KYC Compliance for Crypto Companies: 2025 Checklist
Crypto companies face AML and KYC obligations across multiple jurisdictions simultaneously. Regulators have moved from enforcement ambiguity to aggressive action — the Binance $4.3B settlement, BitMEX convictions, and ongoing OFAC enforcement against crypto protocols make this clear. This guide explains what your crypto company must have in place and what auditors and regulators will look for.
The AML Obligation Map: Which Regulator Controls You
A crypto company's AML obligations depend on where it is incorporated, where it operates, and where its customers are located. This creates multi-jurisdictional exposure for most growth-stage crypto companies.
| Jurisdiction | Regulator | Regime | Key Trigger |
|---|---|---|---|
| United States | FinCEN / OFAC | BSA / MSB registration | Serving US customers or operating from US |
| European Union | National FIUs + ECB | AMLD6 / MiCA + TFR | CASP authorization or serving EU clients |
| United Kingdom | FCA | MLR 2017 registration | Operating from UK or serving UK clients |
| UAE (ADGM/DIFC) | FSRA / DFSA | AML Rules for VASPs | VASP license or serving UAE clients |
| Singapore | MAS | PSA license | DPT services to Singapore users |
| Global | FATF | Travel Rule (Rec. 16) | Transfers ≥$1,000/€1,000 between VASPs |
The AML Program: Five Required Components
Most national AML frameworks (derived from FATF Recommendations) require a written AML program with five components:
- Policies and procedures: Written AML policies covering customer onboarding, transaction monitoring, SAR filing, record-keeping, and staff training. Must be approved by senior management and reviewed annually.
- Designated compliance officer: A named individual responsible for AML compliance. For small companies, this is often the CEO or CFO initially, but the role must be clearly assigned and have the authority and budget to act.
- Ongoing employee training: AML training for all employees who interact with customers or transactions, documented with completion records. Must cover red flags, reporting obligations, and consequences of non-compliance.
- Independent testing: Annual review of the AML program by an independent party (internal audit, external consultant, or external auditor) to assess effectiveness and identify gaps. This is separate from the compliance officer's ongoing monitoring.
- Customer due diligence (CDD): Procedures for verifying customer identity at onboarding (KYC), ongoing monitoring, and enhanced due diligence for high-risk customers. Includes beneficial ownership verification for corporate customers.
FATF Travel Rule Implementation
The FATF Travel Rule requires VASPs to pass originator and beneficiary information alongside crypto transfers above the threshold. Implementation requires:
- Data collection: Collect and verify originator and beneficiary information at account creation and at the time of each covered transfer
- Counterparty VASP identification: Determine whether the receiving address belongs to a VASP (using VASP directories, blockchain analytics, or IP/domain analysis) — you can only send Travel Rule data to another VASP
- Data transmission: Integrate with a Travel Rule solution (Notabene, Sygna Bridge, OpenVASP, TRM Sunrise, Shyft Network) to send structured data securely to counterparty VASPs
- Receiving and screening: Receive incoming Travel Rule data from counterparty VASPs and screen against sanctions lists before processing the transfer
- Unhosted wallet handling: When the receiving address is an unhosted (self-custodied) wallet, most jurisdictions require collecting beneficial owner information above enhanced thresholds
- Record-keeping: Retain Travel Rule records for the mandated period (5 years under FATF recommendations; specific retention periods vary by jurisdiction)
Transaction Monitoring: What to Watch For
Transaction monitoring is the operational core of ongoing AML compliance. Effective systems flag patterns including:
- Structuring — multiple transactions just below reporting thresholds
- Rapid movement — funds received and immediately withdrawn or transferred to external wallets
- High-risk counterparties — transactions involving addresses associated with darknet markets, mixers, or sanctions targets (blockchain analytics required)
- Unusual geography — transactions inconsistent with the customer's stated location or risk profile
- Activity inconsistent with profile — large volumes inconsistent with the customer's stated purpose or financial profile
- Interaction with sanctioned addresses — any interaction with OFAC-listed addresses triggers mandatory blocking and reporting
Blockchain analytics tools (Chainalysis, Elliptic, TRM Labs) automate on-chain counterparty screening. These are no longer optional for regulated crypto businesses — they are expected by regulators as part of a reasonable transaction monitoring program.
Counterparty Due Diligence: Contracts and On-Chain Screening
Beyond individual customer KYC, crypto companies transacting with institutional counterparties need to verify that the counterparty entity is itself compliant:
- Obtain copies of the counterparty's AML program policies and VASP registration/license
- Verify the counterparty appears in FATF-equivalent jurisdiction and is not subject to sanctions
- Screen the counterparty's wallet addresses against blockchain analytics before large transfers
- Execute a written counterparty agreement that includes AML representations and audit rights
- Review counterparty on an annual basis or upon material changes to the relationship
Get a counterparty risk assessment — BRAI
BRAI generates counterparty risk reports covering AML/KYC posture, regulatory exposure across MiCA, VARA, and FinCEN frameworks, and sanctions screening. Used by crypto GCs and compliance officers before institutional transactions. Reports from $149.
Frequently Asked Questions
Which AML regulations apply to crypto companies?
Crypto companies face AML obligations from multiple jurisdictions depending on where they operate and where their customers are located. Key frameworks: FinCEN (US) — crypto exchanges and custodians are Money Services Businesses (MSBs) required to register and implement AML programs; EU AMLD6 — CASPs authorized under MiCA are subject to EU AML requirements including the Transfer of Funds Regulation (TFR); FATF Recommendations — the global standard that most national regulators implement, including the Travel Rule for transfers above $1,000/€1,000; UK FCA — crypto firms must register with the FCA under the Money Laundering Regulations 2017.
What does the FATF Travel Rule require for crypto?
The FATF Travel Rule (Recommendation 16, extended to virtual assets) requires Virtual Asset Service Providers (VASPs) to collect, verify, and transmit originator and beneficiary information for crypto transfers above $1,000/€1,000. The required information: originator name, account number (crypto address), physical address or national identity number or date and place of birth; beneficiary name and account number. VASPs must have technical capability to send and receive this data with counterparty VASPs — compliance requires integration with Travel Rule solutions (Notabene, Sygna Bridge, TRM, etc.).
Does my DeFi protocol need to implement KYC?
DeFi protocols face regulatory uncertainty, but regulators are actively closing the gap. The FATF 2021 updated guidance suggests that DeFi protocols with controlling developers or founders may be treated as VASPs. US regulators (FinCEN, OFAC) have taken enforcement action against DeFi protocols (Tornado Cash) and have signaled that "DAPP" developers can bear compliance obligations. EU MiCA does not directly regulate truly decentralized protocols, but its definition of "decentralized" is narrow. If your protocol has admin keys, upgrade rights, fee collection, or governance power concentrated among identifiable parties, you likely have compliance obligations.
What does a KYC process for a crypto company look like?
A standard crypto company KYC process: (1) Identity verification — collect government-issued ID (passport, national ID), proof of address, selfie/liveness check. (2) Document verification — automated or manual review of documents against document databases for fraud signals. (3) Sanctions screening — check name against OFAC SDN, EU consolidated list, UN sanctions, and other relevant lists before onboarding. (4) PEP screening — check if the individual is a Politically Exposed Person, which triggers enhanced due diligence. (5) Risk scoring — assign a risk tier (low/medium/high) based on jurisdiction, transaction patterns, PEP/sanctions status. (6) Ongoing monitoring — transaction monitoring for suspicious patterns; periodic re-verification (annual for high-risk, biennial for standard). (7) SAR filing — file a Suspicious Activity Report when suspicious activity is detected above thresholds.
What is Enhanced Due Diligence (EDD) and when is it required?
Enhanced Due Diligence is an intensified version of standard KYC applied to high-risk customers. EDD triggers: customers from high-risk jurisdictions (FATF grey/blacklist countries, or countries with weak AML regimes); Politically Exposed Persons (government officials and their close associates); customers with unusual transaction patterns or unexplained wealth; customers in high-risk business categories (gambling, cash-intensive businesses, arms dealing). EDD process typically includes: source-of-funds documentation; source-of-wealth documentation; senior management approval for onboarding; more frequent periodic reviews; enhanced transaction monitoring with lower alert thresholds.
What are the penalties for AML non-compliance in crypto?
AML penalties in crypto are severe and increasing. US examples: BitMEX — $100M DOJ settlement + $100M CFTC penalty for failing to implement AML/KYC; Binance — $4.3B DOJ settlement (2023) for systematic AML failures; Coinbase — $100M settlement with NYDFS for KYC failures. EU: MiCA + AMLA will allow fines up to €5M or 10% of annual revenue for serious AML violations. Beyond fines: criminal prosecution of founders and executives, license revocation, and reputational damage that destroys institutional partnerships.
Related: AML Regulation Hub → enforcement history, penalty tracker, and compliance checklist