Crypto

KYC and AML in crypto, explained

KYC and AML in crypto explained: what identity checks and anti-money-laundering rules mean, why exchanges verify you, and how the Travel Rule fits in.

KYC and AML in crypto, explained

Quick answer

KYC (Know Your Customer) is the identity check a regulated crypto platform runs on you; AML (Anti-Money Laundering) is the broader programme it feeds, from transaction monitoring to sanctions screening and reporting. The obligations land on intermediaries, not individuals, and the precise rules vary by jurisdiction.

Key points

  • KYC verifies your identity; AML is the broader monitoring programme it feeds
  • Rules extend existing anti-money-laundering law to crypto businesses
  • FATF sets the global standards; national bodies like FinCEN enforce them
  • The Travel Rule sends sender and recipient data between regulated firms
  • Obligations fall on intermediaries, not on individuals holding their own assets

Ever wondered why an exchange makes you photograph your passport before it’ll let you trade? That’s KYC and AML doing their job. KYC (“Know Your Customer”) and AML (“Anti-Money Laundering”) are the identity checks and monitoring rules that regulated crypto businesses are legally bound to run, all aimed at keeping criminals out of the financial system. KYC is the narrow step where a platform confirms who you are. AML is the wider programme it feeds — ongoing monitoring, plus record-keeping and a duty to report anything that smells off. Below, we unpack what these obligations are, why exchanges want your documents, and how the pieces fit together.

One caveat first. This is a general explainer, nothing more. The specific obligations, thresholds and documents differ by jurisdiction, so read the examples below as illustrations rather than the exact rules that bind you where you live.

What AML is trying to stop

Anti-money-laundering law exists to make disguising the proceeds of crime as clean money genuinely hard, and to choke off financing for terrorism and the evasion of sanctions. None of this began with crypto. It predates it by decades. The United States Bank Secrecy Act, to take one example, has long obliged financial institutions to keep records and report certain transactions. As crypto matured, regulators mostly stretched these existing frameworks over businesses dealing in virtual assets rather than writing brand-new ones from a blank page.

The global anchor is the Financial Action Task Force — FATF — an intergovernmental body that sets AML standards its member countries then fold into national law. FATF’s recommendations treat crypto exchanges and similar firms as “Virtual Asset Service Providers” (VASPs) and expect them to carry broadly the same obligations as banks.

KYC: verifying who you are

KYC is the customer-identification piece of an AML programme. Open an account on a regulated exchange and it’ll typically collect and check:

  • Identity, via government-issued documents such as a passport or driving licence.
  • Proof of address — often a utility bill or a bank statement.
  • A liveness or selfie check, confirming the document actually belongs to the person holding it up to the camera.
  • Risk information, such as source of funds on larger accounts.

You’ll sometimes see this called Customer Due Diligence, or CDD. For higher-risk customers, firms escalate to Enhanced Due Diligence (EDD) — deeper checks, closer ongoing scrutiny. And the point isn’t bureaucracy for its own sake. It pins a verified identity to an account, so that every bit of monitoring that follows actually means something.

From KYC to ongoing monitoring

Verifying identity once is only the opening move. A full AML programme runs long past onboarding, and usually takes in:

  • Transaction monitoring to flag patterns that reek of layering, structuring, or other laundering techniques.
  • Sanctions and watchlist screening against lists that governments keep updated.
  • Record-keeping, so identity and transaction data can be produced if authorities come knocking.
  • Suspicious Activity Reports (SARs), filed with the national financial-intelligence unit when something looks wrong.

In the United States, FinCEN — the Financial Crimes Enforcement Network — runs much of this, and it has published guidance making clear that money-transmission rules reach many crypto businesses. Firms are expected to appoint a compliance officer, train their staff, and keep the whole programme current instead of setting it up once and wandering off.

The Travel Rule

One crypto-specific obligation earns its own heading, mainly because it blindsides users. FATF’s Recommendation 16 — nicknamed the “Travel Rule” almost everywhere — says that when value above a set threshold moves between VASPs, certain originator and beneficiary details have to “travel” alongside the transfer, much as they do on a bank wire. The threshold FATF recommends is 1,000 USD or EUR, though countries implement it in their own ways.

In practice, a regulated exchange sending crypto to another regulated exchange might share the sender’s and recipient’s identifying details behind the scenes. It’s a compliance data exchange between institutions. It doesn’t touch the on-chain transaction itself. Knowing this clears up something that baffles a lot of people: why a regulated platform occasionally asks where a withdrawal is heading.

A risk-based approach, not one-size-fits-all

Modern AML frameworks are “risk-based” — a slightly fancy way of saying firms are expected to scale their scrutiny to the risk a customer or transaction genuinely presents, rather than treating everyone identically. A small retail account funded from a local bank sits at one end of the spectrum. A high-value account with money threaded through several jurisdictions sits at the other, pulling far more attention. That’s why two people can have wildly different onboarding experiences on the very same platform — and why a previously quiet account can suddenly trigger questions the moment its behaviour shifts.

The risk-based idea also explains why compliance is never truly “finished”. Firms periodically re-verify customers and refresh their sense of who they’re dealing with, then re-screen against updated sanctions lists. So a platform asking you to reconfirm details you handed over a year ago is usually just running this routine review. It isn’t singling you out.

Why custody type changes the picture

KYC and AML obligations attach to businesses that hold or exchange assets for other people. That’s the hinge the whole thing swings on. It’s why a custodial platform, which controls your keys, runs full identity checks, while self-custodial software — where you alone hold the keys — generally won’t put you through KYC at all. The law aims at intermediaries. So the more an intermediary is involved, the more identity and monitoring you should expect. It’s also why the same person can face heavy verification on an exchange yet none whatsoever when shuffling funds between their own wallets.

What it means for you as a user

For an ordinary, honest user, KYC and AML mostly show up as onboarding friction plus the odd query about a transaction. A few practical points to set expectations:

  • Regulated platforms are legally required to verify you. Refuse every identity check and you generally can’t use them — that’s the design, not a bug in it.
  • Accurate information matters, because a mismatch can freeze your access while a firm investigates.
  • Your data gets retained for years under record-keeping rules, so weigh a platform’s security and privacy practices before you sign up.
  • Large or unusual transfers may prompt questions about source of funds. Routine compliance, that — not an accusation.

None of this is a verdict on any one person’s character. It’s simply how the machinery is built to run.

Who these rules actually bind

Here’s a frequent source of confusion: who is the law even pointed at? AML obligations land on businesses that provide financial services — not on individuals, merely for owning or moving their own assets. The exchange, broker or custodian is the “obliged entity” — the one that has to stand up a compliance programme, verify its customers, then file reports when the rules demand. You feel the rules as a customer of such a firm, but you’re not the one legally required to run KYC. Which is why the same activity, pushed through a regulated intermediary, sets off checks, while activity involving no such intermediary generally doesn’t — the very distinction that underpins how different custody models get treated.

Common misunderstandings

A few myths are worth clearing away. KYC is not the same as your money being safe — identity verification does precisely nothing to shield you from a platform’s insolvency or a hack, which is a wholly separate risk. AML rules don’t make crypto “anonymous by default” either; regulated on-ramps and off-ramps bind identities to activity, and the blockchains themselves are usually public and traceable. And clearing KYC on one platform buys you nothing on the next, since every regulated firm has to run its own checks. No shortcuts, sadly.

Bottom line

KYC and AML are the identity-and-monitoring backbone that lets regulated crypto businesses operate inside the law. KYC verifies who you are; AML then puts that verified identity to work through ongoing monitoring and sanctions screening, then reporting whatever a firm is obliged to report — coordinated across borders through FATF and enforced nationally by bodies such as FinCEN. The rules fall on intermediaries, which is exactly why custodial services check you thoroughly and self-custody generally doesn’t. Which checks, thresholds and reports actually apply to you depends on your jurisdiction, so confirm the current requirements with the relevant regulator or a qualified professional.

Sources

  1. FATF Virtual Assets and VASPs
  2. FinCEN Guidance
  3. HMRC Cryptoassets Manual (gov.uk)

Frequently asked questions

What is the difference between KYC and AML?

KYC is the identity-verification step where a platform confirms who you are. AML is the wider programme that KYC feeds into, covering ongoing monitoring, record-keeping, sanctions screening and reporting of suspicious activity.

Why does a crypto exchange need my ID?

Because regulated exchanges are legally treated like other financial institutions and must verify customers under anti-money-laundering law. The exact documents and thresholds differ by jurisdiction.

What is the crypto Travel Rule?

It is FATF Recommendation 16, which requires identifying information about the sender and recipient to accompany transfers above a set threshold between regulated service providers, similar to a bank wire.

Last reviewed: 26 Aug 2026 Next review: 26 Feb 2027 Section: Crypto
Liam Chen
Protocol & security writer · Blockchain mechanics, wallet security, cryptography

Liam Chen writes about how crypto works at the protocol level — consensus, cryptography, wallets and security. He explains mechanisms plainly and cites primary sources.

More by Liam Chen

Related

Crypto

what is cold storage

Discover what is cold storage in crypto, its types, and how it enhances security for digital assets.

cpn_admin · Sep 29, 2026 · 7 min
Crypto

What Is a Stablecoin?

Discover what is a stablecoin and how it maintains a stable value in the volatile world of cryptocurrency.

cpn_admin · Sep 19, 2026 · 9 min