Skip to content
Reference

Crypto AML Compliance: US and UK Obligations for Cryptoasset Firms

The short version

Crypto AML compliance is the application of anti-money laundering, counter-terrorist financing and sanctions obligations to businesses that exchange, transfer or hold cryptoassets for others. FATF Recommendation 15 sets the international baseline and applies the travel rule in Recommendation 16 to virtual asset transfers. In the United States, a business that accepts and transmits convertible virtual currency is generally a money transmitter under FinCEN's rules and must register as a money services business, run an AML program, apply the funds travel rule and file SARs, while OFAC sanctions apply to all U.S. persons. In the United Kingdom, cryptoasset exchange providers and custodian wallet providers are relevant persons under the Money Laundering Regulations 2017, must be registered with the FCA, and must meet the cryptoasset travel rule in Part 7A of those Regulations.

Crypto AML compliance is the body of anti-money laundering (AML), counter-terrorist financing and sanctions obligations that applies to businesses that exchange, transfer, safeguard or administer cryptoassets on behalf of others, together with the controls those businesses use to meet the obligations. The obligations fall mainly on cryptoasset exchanges and custodial wallet providers, and they also affect banks and fintechs whose customers buy, sell, send or receive cryptoassets.

The international baseline: FATF Recommendations 15 and 16

The Financial Action Task Force (FATF) addresses virtual assets in Recommendation 15 (New Technologies) and its Interpretive Note. The FATF amended the standard in 2018 and 2019 so that countries must ensure virtual asset service providers (VASPs) are regulated for AML and counter-terrorist financing purposes, licensed or registered, and subject to effective supervision. The FATF Glossary defines a VASP by five activities conducted as a business for another person: exchange between virtual assets and fiat currencies, exchange between forms of virtual assets, transfer of virtual assets, safekeeping or administration of virtual assets, and financial services related to an issuer's offer or sale of a virtual asset.

Paragraph 7(b) of the Interpretive Note to Recommendation 15 applies the wire transfer requirements of Recommendation 16 to virtual asset transfers. Originating VASPs are to obtain and hold required and accurate originator information and required beneficiary information, submit it to the beneficiary VASP, and make it available to authorities on request. Countries may adopt a de minimis threshold of USD/EUR 1,000, below which a reduced data set applies. This is commonly called the travel rule.

The FATF's Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers (October 2021) explains how the standard applies, including to stablecoins, peer-to-peer transactions and the travel rule. In June 2025 the FATF adopted revisions to Recommendation 16 aimed chiefly at cross-border payment messages, with implementation expected by 2030.

United States framework

Money transmitter status and MSB registration

The Bank Secrecy Act regulations define a money transmitter as a person that accepts "currency, funds, or other value that substitutes for currency" from one person and transmits it to another location or person by any means (31 CFR 1010.100(ff)(5)). FinCEN's guidance Application of FinCEN's Regulations to Certain Business Models Involving Convertible Virtual Currencies (FIN-2019-G001, May 9, 2019) applies that definition to convertible virtual currency (CVC). Under it, a CVC exchanger and a hosted wallet provider that controls customer value are generally money transmitters; a person using an unhosted wallet to buy goods or services on the person's own behalf is not; and an anonymizing services provider, commonly called a mixer, is a money transmitter.

A money services business (MSB) must register with FinCEN, whether or not it holds a state license (31 CFR 1022.380). Registration is due within 180 days after the business is established, is renewed every two years, and includes a list of the business's agents. Each MSB must maintain a written, risk-based AML program reasonably designed to prevent its use for money laundering and terrorist financing (31 CFR 1022.210). State licensing is separate and is covered in money transmitter licensing.

The funds travel rule and recordkeeping

For a transmittal of funds of $3,000 or more, the transmittor's financial institution must include specified information in the transmittal order, including the transmittor's name, address and account number and the amount, and intermediary institutions must pass it on (31 CFR 1010.410(f)). Nonbank financial institutions must also keep records of such transmittals (31 CFR 1010.410(e)). FIN-2019-G001 states that transactions involving CVC qualify as transmittals of funds and may fall within the travel rule, and that a hosted wallet provider must comply according to its position in the chain, whether the information travels in the transmittal order itself or is sent separately. BSA records are generally kept for five years (31 CFR 1010.430(d)).

In October 2020, FinCEN and the Federal Reserve Board proposed to lower the threshold for funds transfers that begin or end outside the United States from $3,000 to $250 and to clarify that the rules apply to CVC and to digital assets with legal tender status. As of September 2026 the proposal had not been adopted as a final rule, and the $3,000 threshold remains in force.

Suspicious activity reporting

An MSB, including a CVC money transmitter, must file a suspicious activity report (SAR) for a transaction conducted or attempted by, at or through it that involves or aggregates at least $2,000 in funds or other assets where it knows, suspects or has reason to suspect that the transaction involves illicit funds, is designed to evade BSA requirements, has no business or apparent lawful purpose, or uses the MSB to facilitate criminal activity (31 CFR 1022.320(a)(2)). The SAR is due within 30 calendar days after initial detection of the facts that may constitute a basis for filing, and the SAR and its supporting documentation are kept for five years from filing (31 CFR 1022.320).

OFAC sanctions

Sanctions administered by the Office of Foreign Assets Control (OFAC) apply to all U.S. persons, and OFAC states that compliance obligations are the same whether a transaction is denominated in digital currency or fiat currency (OFAC FAQ 560). OFAC may include digital currency addresses in SDN List entries, and it states that those address listings are not likely to be exhaustive (OFAC FAQ 562). OFAC's Sanctions Compliance Guidance for the Virtual Currency Industry (October 2021) notes that civil liability is generally strict and recommends a risk-based program that includes screening and geolocation and IP address controls. The guidance also suggests that firms consider unlisted addresses that share a wallet with, or have transacted with, a listed address, and says blockchain analytics tools may help identify that risk. Blocked virtual currency is reported to OFAC within 10 business days and annually while it remains blocked. The general design of screening is described in sanctions screening program.

United Kingdom framework

The Money Laundering Regulations and FCA registration

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692, the MLRs) list cryptoasset exchange providers and custodian wallet providers as relevant persons (regulation 8(2)(j) and (k)). Regulation 14A defines a cryptoasset exchange provider as a firm that, by way of business, exchanges or arranges the exchange of cryptoassets for money, money for cryptoassets, or one cryptoasset for another, or operates a machine that exchanges cryptoassets and money automatically. It defines a custodian wallet provider as a firm that safeguards, or safeguards and administers, cryptoassets or private cryptographic keys on behalf of customers.

Under regulation 56, such a firm must not carry on business unless it is included in the register that the Financial Conduct Authority (FCA) maintains under regulation 54(1A). Regulation 56A contains the transitional provision for firms operating before 10 January 2020. Under regulation 58A, the FCA must refuse registration unless the applicant and its officers, managers and beneficial owners are fit and proper persons. Registered firms also owe the general MLR duties: a business-wide risk assessment (regulation 18), customer due diligence (regulation 28), enhanced due diligence in higher-risk cases (regulation 33), and record keeping for five years (regulation 40).

The cryptoasset travel rule in Part 7A

Part 7A of the MLRs, inserted by SI 2022/860, has applied to cryptoasset transfers since 1 September 2023. Under regulation 64C, the originator's cryptoasset business must send the names of the originator and beneficiary and their account numbers or a unique transaction identifier with each transfer between cryptoasset businesses. Where the transfer is not wholly within the United Kingdom and is at or above the cryptoasset equivalent of £800, additional originator information, such as an address or customer identification number, must also accompany it; for wholly UK transfers it is provided on request within three working days. The £800 figure was substituted with effect from 30 June 2026 by SI 2026/621, replacing the earlier euro-denominated threshold. The beneficiary's cryptoasset business must check for missing or non-corresponding information before making the cryptoasset available, decide on a risk basis whether to delay or return the transfer, and report repeated failures by a counterparty to the FCA (regulation 64D). For transfers to or from an unhosted wallet, regulation 64G allows the business to request information from its own customer and prohibits it from making the cryptoasset available if requested information is not received.

Suspicious activity reports, system priorities and sanctions

UK firms in the regulated sector report suspicions to the National Crime Agency (NCA) under Part 7 of the Proceeds of Crime Act 2002 and Part 3 of the Terrorism Act 2000. In July 2025 the NCA and the FCA, with the Home Office and HM Treasury, published System Priorities 2025, a list of nine economic crime priorities for the regulated sector. Cryptoassets are one of the nine, and the document states that "All Priorities are considered to be equal and are not ranked."

UK financial sanctions are made under the Sanctions and Anti-Money Laundering Act 2018, and designated persons are published on the UK Sanctions List maintained by the Foreign, Commonwealth and Development Office. HM Treasury's Office of Financial Sanctions Implementation (OFSI) lists cryptoasset exchange providers and custodian wallet providers among the relevant firms that must report to OFSI when they know or suspect that a person is designated or has breached sanctions, and must report frozen assets they hold.

The authorisation regime from 2027

The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (SI 2026/102), made on 4 February 2026, create new regulated activities for cryptoassets under the Financial Services and Markets Act 2000. The FCA states that the new regime is expected to come into force on 25 October 2027 and that firms may apply for authorisation or a variation of permission from 30 September 2026. Until the regime begins, MLR registration remains the requirement for cryptoasset exchange providers and custodian wallet providers.

Controls in practice

Firms apply these obligations through controls that adapt conventional AML practice to public blockchains.

Many of these controls are delivered through third-party software. A firm's risk assessment typically records which controls a vendor performs, which remain with the firm, who owns each decision, and how vendor outputs are tested. Outsourcing a control does not transfer the legal obligation.

Application to banks and fintechs

A bank or fintech that does not hold cryptoassets can still send customer funds to, or receive them from, cryptoasset exchanges. Such institutions commonly flag these flows in monitoring, assess exchange counterparties as they would other money services businesses, and consider whether a customer is itself running an unregistered exchange or custody business.

Primary sources

Common questions

What is crypto AML compliance?
Crypto AML compliance is the application of anti-money laundering, counter-terrorist financing and sanctions obligations to businesses that exchange, transfer, safeguard or administer cryptoassets for others, and the controls used to meet those obligations, including customer due diligence, travel rule messaging, address screening, blockchain analytics and suspicious activity reporting.
Is a crypto exchange a money services business in the United States?
Generally, yes. FinCEN's guidance FIN-2019-G001 (May 2019) treats a business that accepts and transmits convertible virtual currency, including an exchanger or a hosted wallet provider, as a money transmitter under 31 CFR 1010.100(ff)(5). A money transmitter must register with FinCEN under 31 CFR 1022.380, maintain an AML program under 31 CFR 1022.210 and file SARs under 31 CFR 1022.320.
What is the crypto travel rule?
The travel rule requires the firm sending a transfer to collect and pass on identifying information about the originator and beneficiary to the receiving firm. FATF applies it to virtual asset transfers through the Interpretive Note to Recommendation 15. In the United States, FinCEN applies the funds travel rule at 31 CFR 1010.410(f) to CVC transmittals of $3,000 or more. In the United Kingdom, Part 7A of the Money Laundering Regulations 2017 has applied since 1 September 2023.
What is the UK travel rule threshold for cryptoasset transfers?
Basic originator and beneficiary information accompanies every transfer between cryptoasset businesses. Additional originator information is required for transfers not wholly within the UK at or above the cryptoasset equivalent of £800, a figure substituted from 30 June 2026 by SI 2026/621 (regulation 64C of the Money Laundering Regulations 2017).
Do cryptoasset firms in the UK need FCA registration?
Yes. Cryptoasset exchange providers and custodian wallet providers must be included in the FCA's register under regulation 56 of the Money Laundering Regulations 2017 and must pass the fit and proper test in regulation 58A. A separate FCA authorisation regime under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 is expected to begin on 25 October 2027.
Are crypto wallet addresses on the OFAC SDN List?
OFAC may include digital currency addresses in SDN List entries. OFAC states in FAQ 562 that these listings are not likely to be exhaustive, and its October 2021 guidance for the virtual currency industry suggests firms also consider unlisted addresses associated with a listed address.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.