home
/
services
/
us
/
U.S. Digital Assets β€’ BSA/AML β€’ Financial Crime Compliance

Crypto AML Compliance Services

ComplyFactor helps digital-asset businesses understand and manage the AML risk that comes with handling cryptocurrency β€” onboarding, wallet and customer risk, transaction activity, source and destination of funds, geographic exposure, suspicious activity, and the policies and controls that tie it all together.

Crypto AML compliance isn't a bolt-on to an existing program β€” it changes what the program actually has to account for.

Where risk enters
1
Customer
2
Wallet
3
Transaction
4
Counterparty
5
Geography
The problem

When Crypto Changes the AML Risk Profile

Adding digital assets to a business doesn't just add a new product line β€” it changes how financial-crime risk actually enters the business. Blockchain addresses are pseudonymous, not anonymous, but a name isn't attached to a wallet the way it's attached to a bank account. Value can move across borders and multiple wallets within minutes, creating different monitoring considerations from slower traditional payment flows. A customer relationship that looks low-risk at onboarding can look very different once you see which wallets they're actually transacting with, and some of the same indicators that flag legitimate privacy-conscious use β€” layered transactions, mixing services, transfers through wallets with no clear ownership history β€” can also be how someone tries to obscure where value came from.

None of this makes cryptocurrency inherently illicit; it means the risk indicators are different from a standard fiat account, and a program designed around fiat-only activity may not account for those risks adequately. Translating those risk indicators into actual controls β€” not just acknowledging that they exist β€” is where this engagement starts.

How risk moves through the business
1
Customer
2
Wallet
3
Transaction
4
Counterparty
5
Geography
Where obligations begin

Where U.S. Crypto AML Obligations Begin

Whether a crypto business has BSA/AML obligations, and what they are, depends on what it actually does β€” not on the fact that it touches digital assets. FinCEN's guidance on convertible virtual currency (FIN-2019-G001) draws a line between a β€œuser” who acquires crypto for their own purchases and an β€œadministrator” or β€œexchanger” who accepts and transmits it, or buys and sells it, on behalf of others.

User

Acquires crypto for their own purchases. Not an MSB under FinCEN's regulations.

Administrator / Exchanger

Accepts and transmits crypto, or buys and sells it, on behalf of others. Generally a money transmitter under FinCEN's rules.

Facts & Circumstances

The actual classification depends on the specific business model β€” not the label β€œcrypto business.”

Where the business is a money transmitter under FinCEN's rules, applicable federal obligations can include MSB registration, an AML program, recordkeeping, and reporting requirements. The activity may also raise separate state money-transmitter licensing questions. A platform that never takes custody of customer funds, a business where crypto is incidental to a fiat-rail product, and a full custodial exchange are not automatically in the same position, and getting that classification right matters before any control gets designed. ComplyFactor's FinCEN MSB Registration Services cover the federal filing itself; this page is about the AML program and controls that follow from the classification.

The relationship, stage by stage

A practical way to organize these controls is by stage in the customer relationship:

01

Before Onboarding

Deciding which customer types, products, and jurisdictions the business will actually serve, and which ones it won't.

02

Customer Onboarding

Identity verification and an initial risk rating based on customer type, expected activity, and jurisdiction.

03

Wallet & Account Relationship

Understanding what's actually known about a customer's wallet activity, where that information is available and relevant.

04

Transaction Activity

Monitoring against expected behavior, not just a fixed threshold.

05

Escalation & Investigation

A documented path from an alert to a decision, with the reasoning kept on record.

06

Ongoing Review

Revisiting the risk rating and controls as a customer's actual activity develops, not just at onboarding.

Beyond the documents

Customer Due Diligence in a Digital-Asset Business

Step one

Identity Verification

A government ID, a selfie, an address. Necessary β€” but only the starting point.
What actually matters

Understanding Customer Risk

Customer type, intended activity, jurisdiction, expected behavior, source of funds, ownership/control, and wallet relationship β€” where relevant.

Cryptocurrency customer due diligence is more than a document-collection exercise. Real due diligence connects who the customer says they are to what they're actually likely to do. A wallet relationship can add another layer that a fiat-focused CDD framework may not account for. None of this means every customer needs the same level of scrutiny β€” a retail customer buying a small, occasional amount and an institutional counterparty moving significant volume through complex structures aren't the same due-diligence problem. Where a CDD framework hasn't kept pace with how the business actually onboards customers, that's a logical area to review.

The control flow

Cryptocurrency transaction monitoring starts with understanding what normal activity should look like for the customer, and what would look different.

typical engagement timeline
On-chain and fiat, monitored together
Wallet, exchange and banking-rail activity reviewed as one picture

Expected Activity

Baseline for the customer

Transaction / Wallet Data

Fiat rails and on-chain activity

Alert

Flagged against the baseline

Review

Against context and patterns

Escalation

Where it warrants one

Wallet or address risk information can be a useful input where it's accessible, but it's an input to a decision a person makes, not a replacement for one. ComplyFactor's service focuses on the monitoring framework, control logic, escalation process, and documented decisioning rather than positioning this engagement as a software product.

The connected system

What a Crypto AML Program Needs to Connect

Effective cryptocurrency AML compliance depends on customer risk, transaction monitoring, escalation, reporting, and review functioning as one connected system rather than five separate checkboxes.

A program can work on paper and still fail in practice when the pieces aren't properly connected: a risk assessment that never touches the policies, policies that don't describe how customer controls actually operate, monitoring that isn't tied to the risk ratings customer onboarding produced, investigations with no consistent path to a reporting decision, training that doesn't reflect what staff actually do, and testing that never gets scheduled.

Risk Assessment
Policies
Customer Controls
Transaction Monitoring
Investigation
Reporting
Training
Testing / Review

For a crypto business, some of that connective tissue is genuinely different from a standard fiat MSB program β€” wallet and on-chain risk factors, for instance β€” and some of it is the same underlying AML program work every MSB needs, covered in full on ComplyFactor's BSA/AML Compliance Program Services. This section is specifically about the crypto-specific layer and how it needs to sit inside that broader program, not a restatement of the program itself.

Diagnostic

Useful gaps to test for include:

Onboarding controls built before the business understood its own transaction risk

Customer risk ratings assigned once and never actually feeding into monitoring

Wallet risk information that never reaches the person making an escalation decision

Policies still describing a product lineup the business has since moved past

Escalation procedures with no documented logic behind a decision

Transaction alerts that pile up with no investigation trail

Crypto products added after the AML program was last written

Geographic exposure that's grown since the risk assessment was done

Unclear day-to-day ownership of compliance responsibilities, and banking or payment partner findings acknowledged but never actually closed out

From review to fix

How We Help Turn Crypto AML Gaps Into a Remediation Plan

Current State

Where the program stands today

Risk Exposure

Mapped against actual activity

Control Gaps

Specific, not general

Priorities

What matters most first

Revised Framework

Updated policies and controls

Implementation

Where agreed

Depending on scope, that can include program review, a new or updated risk assessment, policy updates, customer due diligence design, transaction-monitoring framework review, escalation and investigation procedures, remediation planning, a training framework, and implementation support where agreed. Not every engagement touches every one of these; scope is set around what the gap review actually finds.

MODEL-SPECIFIC SCOPING

An exchange holding customer funds, a payment processor that touches crypto only briefly in a settlement flow, a hosted-wallet business, and a fintech adding crypto as a new feature are not the same compliance problem, even though all four might describe themselves as β€œcrypto businesses.”

Exchange

Holds customer funds directly

Payment Processor

Crypto touches a settlement flow briefly

Hosted-Wallet Business

Custodies wallets on customers' behalf

Fintech Adding Crypto

Crypto is a new feature, not the core product

Scoping starts with the actual transaction flow β€” who holds what, when, and where the money and the crypto actually move β€” rather than a template built for a different kind of platform. ComplyFactor's cryptocurrency compliance services focus on AML controls that reflect how the business actually handles digital assets. ComplyFactor scopes this work around U.S. MSB, fintech, and payments business models, coordinates the crypto-specific controls with the broader BSA/AML and sanctions work that may also apply, and delivers documented policies, risk assessments, and remediation plans. Where a program needs rebuilding rather than adjusting, that's part of the conversation too.

Beyond tThe distinctionhe documents

Crypto AML and Sanctions Risk Are Connected β€” But Not the Same

AML
  • Detecting and reporting suspicious activity
  • Tied to money laundering and related financial crime
  • Customer and transaction risk controls
connected, not the same
Sanctions
  • Not transacting with blocked persons, entities, or jurisdictions
  • Applies regardless of whether activity looks suspicious
  • Governed by OFAC's sanctions programs

Depending on their activities and exposure, digital-asset businesses may need to address both AML and sanctions controls, and the two inform each other β€” a wallet or counterparty identified in one control may also be relevant to the other. ComplyFactor's OFAC & Sanctions Compliance Services cover the sanctions side specifically; this page is about the AML controls.

Decision points

A few situations are worth treating as a prompt to look again, rather than waiting for a fixed interval:

Launching crypto functionality
New markets or jurisdictions
New tokens or asset types
Material volume change
New wallet or customer types
New payment corridors
Partner diligence request
Review findings
Regulatory change
faq

FAQs

Does every cryptocurrency business need to register as an MSB?

No. Registration depends on the specific activities involved β€” generally, an administrator or exchanger that accepts and transmits convertible virtual currency, or buys and sells it on behalf of others, falls within FinCEN's money transmitter definition, while a person who only acquires crypto for their own use typically doesn't. The classification is facts-and-circumstances, not automatic.

Can the engagement focus only on customer due diligence or transaction-monitoring controls?

Yes. The engagement can be scoped to a specific control area β€” customer due diligence, transaction monitoring, escalation procedures, or another agreed area β€” rather than requiring a full program rebuild.

What information is useful when starting a crypto AML review?

Typically an overview of the business model and transaction flows, the products and assets involved, the current AML program and risk assessment (if any), the customer profile, the existing monitoring and escalation approach, and any findings from a partner or prior review. The exact scoping request depends on what the engagement covers.

Can a crypto AML review be completed before a new product or crypto feature launches?

Yes β€” where appropriate, the review can be scoped before launch to assess the proposed business model, customer flow, transaction flow, risk factors, and required controls. This isn't a guarantee of approval or launch readiness certification.

Do we need to rebuild our full AML program when adding crypto functionality?

Not necessarily. Depending on the existing program and the new activity, the work may involve targeted updates to the risk assessment, policies, customer controls, monitoring, escalation, or training rather than a complete rebuild.

Can ComplyFactor review both fiat and on-chain transaction controls in the same engagement?

Where relevant to the business model, the engagement can assess how fiat and on-chain activity connect within the monitoring and escalation framework.

Can an engagement focus on AML gaps identified during bank or payment-partner diligence?

Yes β€” where appropriate, the engagement can be scoped around specific findings or control gaps raised during partner diligence or review.

Get started

Discuss Your Crypto AML Requirements With Our Team

Tell us about your digital-asset business model, customer controls, transaction monitoring approach, or a program review that's overdue β€” we'll confirm scope before anything begins.

Scoped to your transaction flow, not a generic template
Gap review with a prioritized remediation plan
Coordinated with registration and sanctions work where relevant

Book a U.S. AML consultation

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.