Crypto AML compliance is the application of anti-money laundering, counter-terrorist financing and sanctions obligations to businesses that exchange, transfer or hold cryptoassets for others. FATF Recommendation 15 sets the international baseline and applies the travel rule in Recommendation 16 to virtual asset transfers. In the United States, a business that accepts and transmits convertible virtual currency is generally a money transmitter under FinCEN's rules and must register as a money services business, run an AML program, apply the funds travel rule and file SARs, while OFAC sanctions apply to all U.S. persons. In the United Kingdom, cryptoasset exchange providers and custodian wallet providers are relevant persons under the Money Laundering Regulations 2017, must be registered with the FCA, and must meet the cryptoasset travel rule in Part 7A of those Regulations.
Crypto AML compliance is the body of anti-money laundering (AML), counter-terrorist financing and sanctions obligations that applies to businesses that exchange, transfer, safeguard or administer cryptoassets on behalf of others, together with the controls those businesses use to meet the obligations. The obligations fall mainly on cryptoasset exchanges and custodial wallet providers, and they also affect banks and fintechs whose customers buy, sell, send or receive cryptoassets.
The international baseline: FATF Recommendations 15 and 16
The Financial Action Task Force (FATF) addresses virtual assets in Recommendation 15 (New Technologies) and its Interpretive Note. The FATF amended the standard in 2018 and 2019 so that countries must ensure virtual asset service providers (VASPs) are regulated for AML and counter-terrorist financing purposes, licensed or registered, and subject to effective supervision. The FATF Glossary defines a VASP by five activities conducted as a business for another person: exchange between virtual assets and fiat currencies, exchange between forms of virtual assets, transfer of virtual assets, safekeeping or administration of virtual assets, and financial services related to an issuer's offer or sale of a virtual asset.
Paragraph 7(b) of the Interpretive Note to Recommendation 15 applies the wire transfer requirements of Recommendation 16 to virtual asset transfers. Originating VASPs are to obtain and hold required and accurate originator information and required beneficiary information, submit it to the beneficiary VASP, and make it available to authorities on request. Countries may adopt a de minimis threshold of USD/EUR 1,000, below which a reduced data set applies. This is commonly called the travel rule.
The FATF's Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers (October 2021) explains how the standard applies, including to stablecoins, peer-to-peer transactions and the travel rule. In June 2025 the FATF adopted revisions to Recommendation 16 aimed chiefly at cross-border payment messages, with implementation expected by 2030.
United States framework
Money transmitter status and MSB registration
The Bank Secrecy Act regulations define a money transmitter as a person that accepts "currency, funds, or other value that substitutes for currency" from one person and transmits it to another location or person by any means (31 CFR 1010.100(ff)(5)). FinCEN's guidance Application of FinCEN's Regulations to Certain Business Models Involving Convertible Virtual Currencies (FIN-2019-G001, May 9, 2019) applies that definition to convertible virtual currency (CVC). Under it, a CVC exchanger and a hosted wallet provider that controls customer value are generally money transmitters; a person using an unhosted wallet to buy goods or services on the person's own behalf is not; and an anonymizing services provider, commonly called a mixer, is a money transmitter.
A money services business (MSB) must register with FinCEN, whether or not it holds a state license (31 CFR 1022.380). Registration is due within 180 days after the business is established, is renewed every two years, and includes a list of the business's agents. Each MSB must maintain a written, risk-based AML program reasonably designed to prevent its use for money laundering and terrorist financing (31 CFR 1022.210). State licensing is separate and is covered in money transmitter licensing.
The funds travel rule and recordkeeping
For a transmittal of funds of $3,000 or more, the transmittor's financial institution must include specified information in the transmittal order, including the transmittor's name, address and account number and the amount, and intermediary institutions must pass it on (31 CFR 1010.410(f)). Nonbank financial institutions must also keep records of such transmittals (31 CFR 1010.410(e)). FIN-2019-G001 states that transactions involving CVC qualify as transmittals of funds and may fall within the travel rule, and that a hosted wallet provider must comply according to its position in the chain, whether the information travels in the transmittal order itself or is sent separately. BSA records are generally kept for five years (31 CFR 1010.430(d)).
In October 2020, FinCEN and the Federal Reserve Board proposed to lower the threshold for funds transfers that begin or end outside the United States from $3,000 to $250 and to clarify that the rules apply to CVC and to digital assets with legal tender status. As of September 2026 the proposal had not been adopted as a final rule, and the $3,000 threshold remains in force.
Suspicious activity reporting
An MSB, including a CVC money transmitter, must file a suspicious activity report (SAR) for a transaction conducted or attempted by, at or through it that involves or aggregates at least $2,000 in funds or other assets where it knows, suspects or has reason to suspect that the transaction involves illicit funds, is designed to evade BSA requirements, has no business or apparent lawful purpose, or uses the MSB to facilitate criminal activity (31 CFR 1022.320(a)(2)). The SAR is due within 30 calendar days after initial detection of the facts that may constitute a basis for filing, and the SAR and its supporting documentation are kept for five years from filing (31 CFR 1022.320).
OFAC sanctions
Sanctions administered by the Office of Foreign Assets Control (OFAC) apply to all U.S. persons, and OFAC states that compliance obligations are the same whether a transaction is denominated in digital currency or fiat currency (OFAC FAQ 560). OFAC may include digital currency addresses in SDN List entries, and it states that those address listings are not likely to be exhaustive (OFAC FAQ 562). OFAC's Sanctions Compliance Guidance for the Virtual Currency Industry (October 2021) notes that civil liability is generally strict and recommends a risk-based program that includes screening and geolocation and IP address controls. The guidance also suggests that firms consider unlisted addresses that share a wallet with, or have transacted with, a listed address, and says blockchain analytics tools may help identify that risk. Blocked virtual currency is reported to OFAC within 10 business days and annually while it remains blocked. The general design of screening is described in sanctions screening program.
United Kingdom framework
The Money Laundering Regulations and FCA registration
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692, the MLRs) list cryptoasset exchange providers and custodian wallet providers as relevant persons (regulation 8(2)(j) and (k)). Regulation 14A defines a cryptoasset exchange provider as a firm that, by way of business, exchanges or arranges the exchange of cryptoassets for money, money for cryptoassets, or one cryptoasset for another, or operates a machine that exchanges cryptoassets and money automatically. It defines a custodian wallet provider as a firm that safeguards, or safeguards and administers, cryptoassets or private cryptographic keys on behalf of customers.
Under regulation 56, such a firm must not carry on business unless it is included in the register that the Financial Conduct Authority (FCA) maintains under regulation 54(1A). Regulation 56A contains the transitional provision for firms operating before 10 January 2020. Under regulation 58A, the FCA must refuse registration unless the applicant and its officers, managers and beneficial owners are fit and proper persons. Registered firms also owe the general MLR duties: a business-wide risk assessment (regulation 18), customer due diligence (regulation 28), enhanced due diligence in higher-risk cases (regulation 33), and record keeping for five years (regulation 40).
The cryptoasset travel rule in Part 7A
Part 7A of the MLRs, inserted by SI 2022/860, has applied to cryptoasset transfers since 1 September 2023. Under regulation 64C, the originator's cryptoasset business must send the names of the originator and beneficiary and their account numbers or a unique transaction identifier with each transfer between cryptoasset businesses. Where the transfer is not wholly within the United Kingdom and is at or above the cryptoasset equivalent of £800, additional originator information, such as an address or customer identification number, must also accompany it; for wholly UK transfers it is provided on request within three working days. The £800 figure was substituted with effect from 30 June 2026 by SI 2026/621, replacing the earlier euro-denominated threshold. The beneficiary's cryptoasset business must check for missing or non-corresponding information before making the cryptoasset available, decide on a risk basis whether to delay or return the transfer, and report repeated failures by a counterparty to the FCA (regulation 64D). For transfers to or from an unhosted wallet, regulation 64G allows the business to request information from its own customer and prohibits it from making the cryptoasset available if requested information is not received.
Suspicious activity reports, system priorities and sanctions
UK firms in the regulated sector report suspicions to the National Crime Agency (NCA) under Part 7 of the Proceeds of Crime Act 2002 and Part 3 of the Terrorism Act 2000. In July 2025 the NCA and the FCA, with the Home Office and HM Treasury, published System Priorities 2025, a list of nine economic crime priorities for the regulated sector. Cryptoassets are one of the nine, and the document states that "All Priorities are considered to be equal and are not ranked."
UK financial sanctions are made under the Sanctions and Anti-Money Laundering Act 2018, and designated persons are published on the UK Sanctions List maintained by the Foreign, Commonwealth and Development Office. HM Treasury's Office of Financial Sanctions Implementation (OFSI) lists cryptoasset exchange providers and custodian wallet providers among the relevant firms that must report to OFSI when they know or suspect that a person is designated or has breached sanctions, and must report frozen assets they hold.
The authorisation regime from 2027
The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (SI 2026/102), made on 4 February 2026, create new regulated activities for cryptoassets under the Financial Services and Markets Act 2000. The FCA states that the new regime is expected to come into force on 25 October 2027 and that firms may apply for authorisation or a variation of permission from 30 September 2026. Until the regime begins, MLR registration remains the requirement for cryptoasset exchange providers and custodian wallet providers.
Controls in practice
Firms apply these obligations through controls that adapt conventional AML practice to public blockchains.
- Customer due diligence. Identity verification and beneficial ownership follow the ordinary rules described in KYC and KYB. Crypto-specific information often includes the wallets a customer controls, expected sources of crypto funds, and device and IP data.
- Travel rule data and counterparty VASP due diligence. The originating firm collects and transmits the required data; the receiving firm checks it against its own customer records. Before exchanging data, firms commonly assess whether the counterparty is a registered or licensed VASP, where it is located, and whether it can protect the data it receives.
- Screening names and addresses. Customers and counterparties are screened by name, and deposit and withdrawal addresses are screened against sanctions list entries that include digital currency addresses.
- Blockchain analytics. Analytics tools trace funds across multiple transfers ("hops") to estimate a wallet's direct and indirect exposure to sanctioned addresses, mixers, darknet markets and venues that do not verify customers.
- Crypto-specific monitoring scenarios. Common scenarios include receipt of proceeds from approval phishing, in which a victim is induced to sign a transaction that authorizes another party to spend the victim's tokens; rapid pass-through, in which deposits are withdrawn to new addresses within a short period; chain-hopping between assets; and structuring below travel rule thresholds. General monitoring design is covered in transaction monitoring.
- Record keeping. Travel rule messages, analytics results at the time of each decision, screening outcomes and case files are retained for the periods in 31 CFR 1010.430 and MLR regulation 40.
Many of these controls are delivered through third-party software. A firm's risk assessment typically records which controls a vendor performs, which remain with the firm, who owns each decision, and how vendor outputs are tested. Outsourcing a control does not transfer the legal obligation.
Application to banks and fintechs
A bank or fintech that does not hold cryptoassets can still send customer funds to, or receive them from, cryptoasset exchanges. Such institutions commonly flag these flows in monitoring, assess exchange counterparties as they would other money services businesses, and consider whether a customer is itself running an unregistered exchange or custody business.
Primary sources
- FATF Recommendations, Recommendation 15 and its Interpretive Note: The VASP licensing or registration requirement and, in paragraph 7(b) of the Interpretive Note, the travel rule for virtual asset transfers.
- FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers (October 2021): Definitions of VA and VASP, stablecoins, peer-to-peer transactions, licensing and registration, travel rule implementation and supervisory cooperation.
- FATF, update to Recommendation 16 on payment transparency (June 2025): Revisions to the wire transfer standard, with implementation expected by 2030.
- FinCEN, FIN-2019-G001, Application of FinCEN's Regulations to Certain Business Models Involving Convertible Virtual Currencies (May 9, 2019): Money transmitter status of CVC exchangers, hosted wallet providers and anonymizing services; application of the funds travel rule to CVC.
- 31 CFR 1010.100(ff)(5): Definition of money transmitter.
- 31 CFR 1022.380: Registration of money services businesses with FinCEN.
- 31 CFR 1022.210: AML program requirement for money services businesses.
- 31 CFR 1010.410(e) and (f): Recordkeeping and the funds travel rule for transmittals of $3,000 or more.
- 31 CFR 1010.430: Five-year retention period for BSA records.
- FinCEN and Federal Reserve Board, proposed rule on the funds transfer threshold and CVC (October 27, 2020): Proposal to lower the cross-border threshold to $250 and clarify application to CVC; not adopted as a final rule as of September 2026.
- 31 CFR 1022.320: Suspicious activity reporting by money services businesses: $2,000 threshold, 30-day filing, five-year retention.
- OFAC, Sanctions Compliance Guidance for the Virtual Currency Industry (October 2021): Risk-based sanctions programs, geolocation controls, blocked virtual currency reporting and blockchain analytics.
- OFAC FAQs 560 and 562: Equal obligations for digital and fiat currency; digital currency addresses on the SDN List are not likely to be exhaustive.
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692): Regulations 8, 14A, 18, 28, 33, 40, 54, 56, 56A and 58A, and Part 7A (cryptoasset transfers).
- The Money Laundering and Terrorist Financing (Amendment) (No. 2) Regulations 2022 (SI 2022/860): Inserted Part 7A, in force 1 September 2023.
- The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621): Substituted the £800 threshold in regulations 64C(4) and 64G(1)(b) from 30 June 2026.
- NCA and FCA, System Priorities 2025 (July 2025): Nine economic crime priorities for the regulated sector, including cryptoassets; the priorities are not ranked.
- OFSI, UK financial sanctions general guidance: Reporting obligations of relevant firms, including cryptoasset exchange providers and custodian wallet providers.
- The UK Sanctions List (FCDO): Persons designated under regulations made under the Sanctions and Anti-Money Laundering Act 2018.
- The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (SI 2026/102): New regulated cryptoasset activities under FSMA 2000.
- FCA, A new regime for cryptoasset regulation: Expected commencement on 25 October 2027 and the application window opening 30 September 2026.