Log in Sign Up

KYC, AML, and VASPs: How crypto compliance works

Sep 14, 2026

The promise of permissionless finance looks good on paper. In practice, it's also made crypto a vehicle for money laundering, sanctions evasion, and other financial crime. That's the backdrop against which businesses operating in crypto now navigate a spectrum of legal and regulatory obligations largely borrowed from traditional finance.

TL;DR

  • "Crypto compliance" isn't a defined regulatory term. There's no single universal framework — just a patchwork of AML, KYC, and CFT obligations that mirror what traditional finance already follows.
  • VASPs (Virtual Asset Service Providers) carry the heaviest direct regulatory burden, and the definition is broader than most people assume — it can stretch to include certain DeFi operators, stablecoin issuers, and even some NFT marketplaces.
  • KYC verifies who you are. AML watches what you do with your funds. CFT narrows that focus specifically toward terrorism financing. All three usually get grouped together in practice.
  • The Travel Rule requires platforms to pass along sender and receiver information on transactions between VASPs, similar to how traditional wire transfers work.
  • Blockchain's permanence cuts both ways — it helps criminals obscure fund origins through layering, but it also gives investigators a permanent record to reconstruct exactly what happened.

What "crypto compliance" means in practice

Public blockchains like Bitcoin let anyone join, transact, and build on top of the network without asking permission from anyone. At the protocol level, there's no built-in identity check of any kind.

Compliance, more broadly, means following the laws, regulations, or industry guidelines set by governments or regulatory bodies — financial rules, data privacy laws, and so on. But "crypto compliance" isn't a defined regulatory term with one agreed-upon meaning. There's no universally accepted framework that spells out exactly what it requires.

Instead, exchanges, custodians, brokers, wallet providers, and OTC desks each navigate their own patchwork of rules depending on where they operate. The general logic, though, is simple: if an activity would trigger compliance obligations in traditional finance, the same obligations tend to apply when that same activity happens in crypto.

That means AML (anti-money laundering), KYC (know your customer), and CFT (combating the financing of terrorism) all show up regularly, borrowed almost wholesale from how banks and other financial institutions already operate.

VASPs: The entities carrying the heaviest load

Platforms registered as Virtual Asset Service Providers carry the most direct regulatory weight. The term, defined by the Financial Action Task Force (FATF), covers any business involved in swapping, transferring, safeguarding, or administering virtual assets on behalf of customers. That includes:

  • Centralized exchanges
  • Custodial wallet providers
  • OTC desks and brokers
  • Payment processors

TRM Labs has described VASPs as "critical compliance gatekeepers" sitting at the core of global AML enforcement, and for good reason — they carry regulatory responsibilities similar to traditional financial institutions. In the U.S., for example, they're treated as money service businesses subject to standard AML and sanctions laws under the Bank Secrecy Act.

That doesn't mean non-VASP entities get a pass on AML requirements, either. In certain jurisdictions, regulators have gone as far as blacklisting specific smart contracts, mixing tools, or self-hosted wallets outright.

There are also genuine edge cases outlined by Chainalysis, where classification isn't obvious. Some DeFi protocols, despite being technically decentralized, have owners or operators who FATF may consider VASPs — though this classification remains contested and unresolved in many jurisdictions.

Stablecoin issuers can qualify too, if their tokens are used for payments, value transfer, or exchange against fiat or other crypto. NFT marketplaces can fall into the same category, depending on how the NFTs are actually being used — specifically when they function less like collectibles and more like payment or investment instruments.

MiCA: EU's answer to the patchwork problem

Most of what's covered so far is a patchwork of national rules, FATF guidance, and case-by-case classification questions that vary depending on where a platform happens to operate. MiCA (Markets in Crypto-Assets Regulation) is the EU's attempt to replace that patchwork, at least within its own borders, with one consistent rulebook.

MiCA sets a single framework that applies across the entire EU, covering everything from how crypto-asset service providers get authorized to how stablecoins are issued and how consumers are protected from fraud and market manipulation. Full enforcement began on December 30, 2024.

The regulation doesn't stop at companies headquartered in Europe — non-EU platforms serving EU customers fall under its scope too, which means a US or Asia-based exchange with European users can't simply treat MiCA as someone else's problem.

For VASPs specifically, MiCA effectively formalizes many of the same obligations already covered above — AML, KYC, transaction transparency — but bundles them into a single licensing regime. Get authorized in one EU member state, and that authorization generally carries across the rest of the bloc.

In terms of AML, getting a MiCA license entails dual compliance — it proves a business can legally operate, but it must also run active AML defenses.

Just roughly 200 out of 1200 crypto VASPs transitioned to CASPs as of June 2026. Source: Finance Magnates

On the downside, legal experts note the heavy bureaucratic and financial costs for businesses, alongside other hurdles for EU-operating businesses. By mid-2026, Europe saw an estimated 90% drop in firms transitioning from old national VASP registrations to the unified Crypto-Asset Service Provider (CASP) license.

The transitional "grandfathering" grace period for the VASP-CASP transition expired across all European Economic Area (EEA) states on July 1, 2026. This means any exchange, custodian, or wallet provider operating in the EU without an official CASP license is now breaking EU law. This forced dozens of unlicensed platforms to cease services for EU clients.

Separately, MiCA's stablecoin rules — which require the issuers of fiat-pegged tokens to hold EU authorization — has barred USDT from MiCA-licensed exchanges, as Tether never sought MiCA authorization.

The key terms, explained

KYC (know your customer)

KYC is the mandatory identity-verification process businesses use to confirm who their users actually are. It typically involves collecting official government documents — a passport, driver's license, or national ID — and matching the person to that document through a biometric check like facial recognition or liveness detection. Users usually also need to confirm their address through a utility bill or bank statement.

This protects both users and platforms from identity theft and fraudulent accounts. Centralized exchanges commonly restrict withdrawals or trading for accounts that haven't completed full verification.

KYC checklist. Source: ComplyCube

That said, KYC sits in obvious tension with crypto's original pitch — a version of finance without gatekeepers, built around not having to hand over personal data to participate.

AML (anti-money laundering)

AML covers the policies and controls designed to detect and prevent criminals from hiding illegally obtained funds through crypto platforms and networks. It extends well beyond onboarding, into ongoing transaction monitoring and internal controls.

Money launderers exploit the pseudonymous, borderless nature of blockchains to obscure where funds actually came from — usually fraud, theft, drug trafficking, or ransomware. In 2025, the total value laundered through crypto exceeded $60 billion.

The process generally follows three stages, as described by TRM Labs:

  • Placement — moving funds into the crypto system, often through peer-to-peer exchanges or Bitcoin ATMs
  • Layering — breaking the link between funds and their origin through a sequence of complex transactions, frequently hopping across blockchains, converting into privacy coins like Monero, or routing through mixers and tumblers
  • Integration — withdrawing the "cleaned" funds as apparently legitimate income, often by converting back to fiat through a compliant exchange or purchasing high-value goods
Money laundering through crypto. Source: DX Compliance

Blockchain's permanence works in the other direction too, though. Because every transaction is recorded forever, blockchain analytics tools can reconstruct these schemes after the fact. Platforms increasingly rely on automated systems that scan public ledgers, score wallet risk, and flag suspicious patterns — like rapid in-and-out movement of large sums.

CFT (combating the financing of terrorism)

CFT overlaps heavily with AML, just with a narrower focus — which is why most regulatory frameworks group them together as "AML/CFT."

Like money laundering, terrorism financing generally moves through three stages: soliciting money for a group or act, moving it, and ultimately using it. CFT frameworks exist to disrupt that flow and close off routes criminals might otherwise use to sidestep AML rules entirely.

Crypto platforms operating as VASPs are required to gather and disclose specific information about the senders and beneficiaries of transactions. Most follow standards set by FATF, which apply across more than 200 jurisdictions globally.

The Travel Rule

The Travel Rule is a core piece of AML/CFT enforcement. Similar to wire transfer requirements in traditional banking, it requires VASPs to gather, verify, and pass along identifying information about the sender and receiver whenever a crypto transaction moves between platforms.

Say Alice sends Bitcoin to Bob, moving funds from her exchange to his. That identifying information travels along with the transfer itself, and each platform is expected to sanction-screen its own user and perform due diligence on the counterparty platform before accepting or rejecting the transaction.

How the Travel Rule works. Source: Notabene

Transaction monitoring

Compliance systems continuously analyze user transactions to detect patterns associated with financial crime — things like funds sent in rapid succession to multiple new addresses, or a transfer received directly from a known mixing service. Flagged activity gets monitored on an ongoing basis rather than reviewed once and forgotten.

Sanctions screening

Regulatory bodies like the U.S. Office of Foreign Assets Control (OFAC) publish lists of wallet addresses linked to sanctioned individuals, entities, and jurisdictions. Crypto operators are required to check their users and transactions against these lists before processing activity.

Suspicious activity reports (SARs)

When a VASP or financial institution detects activity that looks suspicious, it files a formal Suspicious Activity Report, flagging the transaction for review by regulators. Failing to file when required can lead to significant enforcement action — regulators have increasingly treated missed or delayed SARs as a serious compliance failure in their own right, separate from whatever underlying activity triggered the report in the first place.

BitMEX's failure to file SARs between 2014 and 2020 constituted "willful violations of the Bank Secrecy Act," according to the Financial Crimes Enforcement Network (FinCEN). The bureau found the exchange had failed to file a single SAR on at least 588 specific suspicious transactions over that six-year span — including trades connected to darknet markets and unregistered money service businesses. That civil money penalty, assessed by FinCEN in August 2021, totaled $100 million.

Excerpt from FinCEN's assessment of the civil money penalty. Source: FinCEN

Proof of reserves (PoR)

Proof of reserves is how an exchange or custodian shows, in public and verifiable form, that it actually holds enough assets to cover what it owes its customers. It wasn't always standard practice — demand for this kind of transparency spiked sharply after FTX collapsed in 2022.

Most PoR audits rely on cryptographic tools like Merkle trees, which let a user confirm their own balance was counted in the total without exposing anyone's individual account details in the process. It's a meaningful step toward transparency, but it comes with real limits.

Our full guide to proof of reserves covers what the mechanism actually proves, and just as importantly, what it doesn't.

Chain of custody

In a crypto investigation, chain of custody means the fully documented trail an asset takes as it moves from wallet to wallet, platform to platform. When a compliance team traces funds from a suspected illicit source through a series of intermediate wallets to wherever they ultimately land, that unbroken trail is what turns a suspicion into usable evidence.

It's the on-chain equivalent of how physical evidence gets logged and tracked in a criminal case — if a gap opens up anywhere in that trail, the evidence loses much of its value, no matter how suspicious the transaction pattern looks on its own.

Chain of custody, simplified. Source: Educba

This matters for non-VASPs, too

Compliance obligations don't only apply to the platforms filing the paperwork. As enforcement has intensified, the practical reach of AML/CFT rules has widened to catch smart contracts, mixing tools, and even certain self-hosted wallets in specific jurisdictions.

The line between "regulated entity" and "individual user" isn't always as clean as the rulebook suggests, and that ambiguity is exactly why edge cases — DeFi protocols with identifiable operators, stablecoin issuers, NFT marketplaces functioning as payment rails — keep showing up as genuinely unresolved questions rather than settled ones.

Consequences of non-compliance

Beyond financial penalties like BitMEX's $100 million enforcement action, non-compliance can escalate all the way to criminal prosecution, or in extreme cases, the collapse of the business itself.

In late 2023, Binance pled guilty to violating AML, unlicensed money transmitting, and sanctions laws, agreeing to pay $4.3 billion to resolve its criminal liability with U.S. authorities. CEO Changpeng Zhao was later sentenced to four months in prison and ordered to pay a $50 million criminal fine, and stepped down as CEO as part of the resolution.

The DOJ's investigation found that Binance's own internal communications showed its compliance staff were aware the exchange lacked the protocols needed to flag or report transactions for AML risk — meaning the failure wasn't a knowledge gap, but a known, unaddressed one.

Failure to meet AML/KYC rules or reserve requirements has also been the primary driver behind more than 50 crypto firms losing their licenses under MiCA, as of November 2025.

What this means for crypto users

All of this compliance machinery shapes what you experience directly as a user, even if you never think about it in those terms. It's why opening an account somewhere now almost always means submitting ID documents before you can trade — and a transfer can occasionally sit pending while a platform runs a sanctions check.

Choosing a licensed and regulated provider is a must but not a guarantee, as the string of MiCA license revocations and the Binance case make clear. A CASP license or an AML program merely reduces the odds of ending up on a platform that collapses under enforcement action or gets frozen out of a market overnight.

The practical takeaway is fairly simple: platforms that push back against ID checks or seem evasive about their regulatory status are worth treating with real caution, not just mild annoyance.

Regulation caught up. It's not finished.

Crypto's permissionless design was never going to sit comfortably next to a financial system built on identity verification and transaction oversight, and it hasn't. What's emerged instead is a layered set of obligations — KYC at onboarding, AML and CFT running continuously in the background, sanctions screening and SARs catching what falls through — largely adapted from traditional finance rather than built from scratch for crypto specifically.

None of it makes crypto crime-proof. But it does mean the idea that blockchain activity is inherently invisible to regulators is increasingly out of date. The same permanence that lets criminals layer transactions across chains is the same permanence that lets investigators eventually trace them back.

Disclaimer:

The information provided by Clapp ("we,” “us” or “our”) in this report is for general informational purposes only. All investment/financial opinions expressed by Clapp in this report are from personal research and open information sources and are intended as educational material. All outlined information is provided in good faith, however we make no representation or warranty of any kind, express or implied, regarding the accuracy, adequacy, validity, reliability, availability or completeness of any information in this report.