ComplyFactor helps digital-asset businesses understand and manage the AML risk that comes with handling cryptocurrency β onboarding, wallet and customer risk, transaction activity, source and destination of funds, geographic exposure, suspicious activity, and the policies and controls that tie it all together.
Crypto AML compliance isn't a bolt-on to an existing program β it changes what the program actually has to account for.
Adding digital assets to a business doesn't just add a new product line β it changes how financial-crime risk actually enters the business. Blockchain addresses are pseudonymous, not anonymous, but a name isn't attached to a wallet the way it's attached to a bank account. Value can move across borders and multiple wallets within minutes, creating different monitoring considerations from slower traditional payment flows. A customer relationship that looks low-risk at onboarding can look very different once you see which wallets they're actually transacting with, and some of the same indicators that flag legitimate privacy-conscious use β layered transactions, mixing services, transfers through wallets with no clear ownership history β can also be how someone tries to obscure where value came from.
None of this makes cryptocurrency inherently illicit; it means the risk indicators are different from a standard fiat account, and a program designed around fiat-only activity may not account for those risks adequately. Translating those risk indicators into actual controls β not just acknowledging that they exist β is where this engagement starts.
Whether a crypto business has BSA/AML obligations, and what they are, depends on what it actually does β not on the fact that it touches digital assets. FinCEN's guidance on convertible virtual currency (FIN-2019-G001) draws a line between a βuserβ who acquires crypto for their own purchases and an βadministratorβ or βexchangerβ who accepts and transmits it, or buys and sells it, on behalf of others.
Acquires crypto for their own purchases. Not an MSB under FinCEN's regulations.
Accepts and transmits crypto, or buys and sells it, on behalf of others. Generally a money transmitter under FinCEN's rules.
The actual classification depends on the specific business model β not the label βcrypto business.β
Where the business is a money transmitter under FinCEN's rules, applicable federal obligations can include MSB registration, an AML program, recordkeeping, and reporting requirements. The activity may also raise separate state money-transmitter licensing questions. A platform that never takes custody of customer funds, a business where crypto is incidental to a fiat-rail product, and a full custodial exchange are not automatically in the same position, and getting that classification right matters before any control gets designed. ComplyFactor's FinCEN MSB Registration Services cover the federal filing itself; this page is about the AML program and controls that follow from the classification.
A practical way to organize these controls is by stage in the customer relationship:
Deciding which customer types, products, and jurisdictions the business will actually serve, and which ones it won't.
Identity verification and an initial risk rating based on customer type, expected activity, and jurisdiction.
Understanding what's actually known about a customer's wallet activity, where that information is available and relevant.
Monitoring against expected behavior, not just a fixed threshold.
A documented path from an alert to a decision, with the reasoning kept on record.
Revisiting the risk rating and controls as a customer's actual activity develops, not just at onboarding.
Cryptocurrency customer due diligence is more than a document-collection exercise. Real due diligence connects who the customer says they are to what they're actually likely to do. A wallet relationship can add another layer that a fiat-focused CDD framework may not account for. None of this means every customer needs the same level of scrutiny β a retail customer buying a small, occasional amount and an institutional counterparty moving significant volume through complex structures aren't the same due-diligence problem. Where a CDD framework hasn't kept pace with how the business actually onboards customers, that's a logical area to review.
Cryptocurrency transaction monitoring starts with understanding what normal activity should look like for the customer, and what would look different.
Baseline for the customer
Fiat rails and on-chain activity
Flagged against the baseline
Against context and patterns
Where it warrants one
Wallet or address risk information can be a useful input where it's accessible, but it's an input to a decision a person makes, not a replacement for one. ComplyFactor's service focuses on the monitoring framework, control logic, escalation process, and documented decisioning rather than positioning this engagement as a software product.
Effective cryptocurrency AML compliance depends on customer risk, transaction monitoring, escalation, reporting, and review functioning as one connected system rather than five separate checkboxes.
A program can work on paper and still fail in practice when the pieces aren't properly connected: a risk assessment that never touches the policies, policies that don't describe how customer controls actually operate, monitoring that isn't tied to the risk ratings customer onboarding produced, investigations with no consistent path to a reporting decision, training that doesn't reflect what staff actually do, and testing that never gets scheduled.
For a crypto business, some of that connective tissue is genuinely different from a standard fiat MSB program β wallet and on-chain risk factors, for instance β and some of it is the same underlying AML program work every MSB needs, covered in full on ComplyFactor's BSA/AML Compliance Program Services. This section is specifically about the crypto-specific layer and how it needs to sit inside that broader program, not a restatement of the program itself.
Useful gaps to test for include:
Onboarding controls built before the business understood its own transaction risk
Customer risk ratings assigned once and never actually feeding into monitoring
Wallet risk information that never reaches the person making an escalation decision
Policies still describing a product lineup the business has since moved past
Escalation procedures with no documented logic behind a decision
Transaction alerts that pile up with no investigation trail
Crypto products added after the AML program was last written
Geographic exposure that's grown since the risk assessment was done
Unclear day-to-day ownership of compliance responsibilities, and banking or payment partner findings acknowledged but never actually closed out
Where the program stands today
Mapped against actual activity
Specific, not general
What matters most first
Updated policies and controls
Where agreed
Depending on scope, that can include program review, a new or updated risk assessment, policy updates, customer due diligence design, transaction-monitoring framework review, escalation and investigation procedures, remediation planning, a training framework, and implementation support where agreed. Not every engagement touches every one of these; scope is set around what the gap review actually finds.
An exchange holding customer funds, a payment processor that touches crypto only briefly in a settlement flow, a hosted-wallet business, and a fintech adding crypto as a new feature are not the same compliance problem, even though all four might describe themselves as βcrypto businesses.β
Holds customer funds directly
Crypto touches a settlement flow briefly
Custodies wallets on customers' behalf
Crypto is a new feature, not the core product
Scoping starts with the actual transaction flow β who holds what, when, and where the money and the crypto actually move β rather than a template built for a different kind of platform. ComplyFactor's cryptocurrency compliance services focus on AML controls that reflect how the business actually handles digital assets. ComplyFactor scopes this work around U.S. MSB, fintech, and payments business models, coordinates the crypto-specific controls with the broader BSA/AML and sanctions work that may also apply, and delivers documented policies, risk assessments, and remediation plans. Where a program needs rebuilding rather than adjusting, that's part of the conversation too.
Depending on their activities and exposure, digital-asset businesses may need to address both AML and sanctions controls, and the two inform each other β a wallet or counterparty identified in one control may also be relevant to the other. ComplyFactor's OFAC & Sanctions Compliance Services cover the sanctions side specifically; this page is about the AML controls.
A few situations are worth treating as a prompt to look again, rather than waiting for a fixed interval:
No. Registration depends on the specific activities involved β generally, an administrator or exchanger that accepts and transmits convertible virtual currency, or buys and sells it on behalf of others, falls within FinCEN's money transmitter definition, while a person who only acquires crypto for their own use typically doesn't. The classification is facts-and-circumstances, not automatic.
Yes. The engagement can be scoped to a specific control area β customer due diligence, transaction monitoring, escalation procedures, or another agreed area β rather than requiring a full program rebuild.
Typically an overview of the business model and transaction flows, the products and assets involved, the current AML program and risk assessment (if any), the customer profile, the existing monitoring and escalation approach, and any findings from a partner or prior review. The exact scoping request depends on what the engagement covers.
Yes β where appropriate, the review can be scoped before launch to assess the proposed business model, customer flow, transaction flow, risk factors, and required controls. This isn't a guarantee of approval or launch readiness certification.
Not necessarily. Depending on the existing program and the new activity, the work may involve targeted updates to the risk assessment, policies, customer controls, monitoring, escalation, or training rather than a complete rebuild.
Where relevant to the business model, the engagement can assess how fiat and on-chain activity connect within the monitoring and escalation framework.
Yes β where appropriate, the engagement can be scoped around specific findings or control gaps raised during partner diligence or review.
Tell us about your digital-asset business model, customer controls, transaction monitoring approach, or a program review that's overdue β we'll confirm scope before anything begins.