KYC and AML in crypto, explained
KYC and AML in crypto explained: what identity checks and anti-money-laundering rules mean, why exchanges verify you, and how the Travel Rule fits in.

Quick answer
KYC (Know Your Customer) is the identity check a regulated crypto platform runs on you. AML (Anti-Money Laundering) is the wider programme it feeds — monitoring, sanctions screening and reporting. Both fall on intermediaries, not individuals, and the exact rules differ by jurisdiction.
Key points
- KYC verifies your identity; AML is the broader monitoring programme it feeds
- Rules extend existing anti-money-laundering law to crypto businesses
- FATF sets the global standards; national bodies like FinCEN enforce them
- The Travel Rule sends sender and recipient data between regulated firms
- Obligations fall on intermediaries, not on individuals holding their own assets
Ever wondered why an exchange makes you photograph your passport before you can trade? That’s KYC and AML at work. KYC (“Know Your Customer”) and AML (“Anti-Money Laundering”) are the identity checks and monitoring rules that regulated crypto businesses have to run to keep criminals out of the financial system. KYC is the narrow step where a platform confirms who you are. AML is the wider programme it feeds — ongoing monitoring, record-keeping, and reporting anything that looks off. This article unpacks what these obligations are, why exchanges want your documents, and how the pieces fit together.
One caveat up front. This is a general explainer. The specific obligations, thresholds and documents differ by jurisdiction, so treat the examples below as illustrations, not the exact rules that bind you where you live.
What AML is trying to stop
Anti-money-laundering law exists to make it hard to disguise the proceeds of crime as clean money, and to choke off financing for terrorism and sanctions evasion. None of this started with crypto — it predates it by decades. The United States Bank Secrecy Act, for one, has long required financial institutions to keep records and report certain transactions. As crypto grew up, regulators mostly stretched these existing frameworks to cover businesses dealing in virtual assets rather than drafting brand-new ones from scratch.
The global anchor here is the Financial Action Task Force, or FATF, an intergovernmental body that sets AML standards its member countries then bake into national law. FATF’s recommendations treat crypto exchanges and similar firms as “Virtual Asset Service Providers” (VASPs) and expect them to shoulder broadly the same obligations as banks.
KYC: verifying who you are
KYC is the customer-identification piece of an AML programme. Open an account on a regulated exchange and it’ll typically collect and check:
- Identity, using government-issued documents such as a passport or driving licence.
- Proof of address — often a utility bill or a bank statement.
- A liveness or selfie check, to confirm the document actually belongs to the person holding it up.
- Risk information, like source of funds on larger accounts.
This is sometimes called Customer Due Diligence, or CDD. For higher-risk customers, firms step up to Enhanced Due Diligence (EDD) — deeper checks and closer ongoing scrutiny. And the goal isn’t bureaucracy for its own sake. It pins a verified identity to an account, so that all the monitoring that comes later actually means something.
From KYC to ongoing monitoring
Verifying identity once is only the opening move. A full AML programme keeps going long after onboarding, and usually includes:
- Transaction monitoring to flag patterns that smell like layering, structuring, or other laundering techniques.
- Sanctions and watchlist screening against lists that governments maintain.
- Record-keeping, so identity and transaction data can be produced if authorities come asking.
- Suspicious Activity Reports (SARs), filed with the national financial-intelligence unit when something looks wrong.
In the United States, FinCEN — the Financial Crimes Enforcement Network — administers much of this, and it has published guidance clarifying that money-transmission rules apply to many crypto businesses. Firms are expected to appoint a compliance officer, train their staff, and keep the whole programme current rather than setting it up once and walking away.
The Travel Rule
One crypto-specific obligation earns its own section, mostly because it catches users off guard. FATF’s Recommendation 16 — widely nicknamed the “Travel Rule” — says that when value above a set threshold moves between VASPs, certain originator and beneficiary details have to “travel” with the transfer, much like they do on a bank wire. The threshold FATF recommends is 1,000 USD or EUR, though countries implement it their own ways.
In practice, a regulated exchange sending crypto to another regulated exchange may share the sender’s and recipient’s identifying details behind the scenes. It’s a compliance data exchange between institutions. It doesn’t touch the on-chain transaction itself. Knowing this helps explain something that puzzles a lot of people: why a regulated platform sometimes asks where a withdrawal is headed.
A risk-based approach, not one-size-fits-all
Modern AML frameworks are “risk-based”, which is a fancy way of saying firms are expected to scale their scrutiny to the risk a customer or transaction actually presents, instead of treating everyone identically. A small retail account funded from a local bank sits at one end of the spectrum. A high-value account with money routed through several jurisdictions sits at the other, and it draws far more attention. That’s why two people can have wildly different onboarding experiences on the very same platform — and why a previously quiet account can suddenly trigger questions the moment its behaviour shifts.
The risk-based idea also explains why compliance is never really “done”. Firms periodically re-verify customers, refresh their picture of who they’re dealing with, and re-screen against updated sanctions lists. So a platform asking you to confirm details you handed over a year ago is usually just running this routine review. It isn’t singling you out.
Why custody type changes the picture
KYC and AML obligations attach to businesses that hold or exchange assets for other people. That’s the hinge. It’s why a custodial platform, which controls your keys, runs full identity checks, while self-custodial software — where you alone hold the keys — generally doesn’t put you through KYC at all. The law is aimed at intermediaries, so the more an intermediary is involved, the more identity and monitoring you should expect. It’s also why the same person can face heavy verification on an exchange yet none when shuffling funds between their own wallets.
What it means for you as a user
For an ordinary, honest user, KYC and AML mostly turn up as onboarding friction plus the occasional query about a transaction. A few practical points help set expectations:
- Regulated platforms are legally required to verify you. Refuse every identity check and you generally can’t use them — that’s the design, not a bug.
- Accurate information matters, because a mismatch can freeze your access while a firm investigates.
- Your data is retained for years under record-keeping rules, so weigh a platform’s security and privacy practices before you sign up.
- Large or unusual transfers may prompt questions about source of funds. That’s routine compliance, not an accusation.
None of this is a judgement on any individual’s risk. It’s simply how the machinery is built to run.
Who these rules actually bind
Here’s a common source of confusion: who is the law even aimed at? AML obligations fall on businesses that provide financial services — not on individuals, simply for owning or moving their own assets. The exchange, broker or custodian is the “obliged entity” that has to build a compliance programme, verify customers and file reports. You feel the rules as a customer of such a firm, but you’re not the one legally required to run KYC. That’s why the same activity, pushed through a regulated intermediary, triggers checks, while activity involving no such intermediary generally doesn’t — the same distinction that underpins how different custody models get treated.
Common misunderstandings
A few myths are worth clearing up. KYC is not the same as your money being safe: identity verification does nothing to shield you from a platform’s insolvency or a hack, which is a completely separate risk. AML rules don’t make crypto “anonymous by default” either — regulated on-ramps and off-ramps tie identities to activity, and the blockchains themselves are usually public and traceable. And clearing KYC on one platform buys you nothing on the next, because every regulated firm has to run its own checks. No shortcuts, unfortunately.
Bottom line
KYC and AML are the identity-and-monitoring backbone that lets regulated crypto businesses operate legally. KYC verifies who you are; AML then puts that verified identity to work through ongoing monitoring, sanctions screening and reporting, coordinated internationally through FATF and enforced nationally by bodies such as FinCEN. The rules land on intermediaries, which is exactly why custodial services check you thoroughly and self-custody generally doesn’t. Which checks, thresholds and reports apply to you depends on your jurisdiction, so verify the current requirements with the relevant regulator or a qualified professional.
Sources
Frequently asked questions
What is the difference between KYC and AML?
KYC is the identity-verification step where a platform confirms who you are. AML is the wider programme that KYC feeds into, covering ongoing monitoring, record-keeping, sanctions screening and reporting of suspicious activity.
Why does a crypto exchange need my ID?
Because regulated exchanges are legally treated like other financial institutions and must verify customers under anti-money-laundering law. The exact documents and thresholds differ by jurisdiction.
What is the crypto Travel Rule?
It is FATF Recommendation 16, which requires identifying information about the sender and recipient to accompany transfers above a set threshold between regulated service providers, similar to a bank wire.
Related
What gas fees actually pay for
Gas fees pay for the computation your transaction needs and ration limited block space. Here is what they actually fund…
Social engineering in crypto: the recurring patterns
Social engineering in crypto: the recurring scam patterns, the psychological levers behind them, and the defence habits that work across…
Seed phrases: what they are and how people lose them
Seed phrases explained: what a recovery phrase is, why it controls your entire wallet, how people lose them, and how…


