Crypto

KYC and AML in crypto, explained

KYC and AML in crypto explained: what identity checks and anti-money-laundering rules mean, why exchanges verify you, and how the Travel Rule fits in.

KYC and AML in crypto, explained

Quick answer

KYC (Know Your Customer) is the identity check a regulated crypto platform runs on you; AML (Anti-Money Laundering) is the wider programme it feeds, covering monitoring, sanctions screening and reporting. Both apply to intermediaries, and the exact rules differ by jurisdiction.

Key points

  • KYC verifies your identity; AML is the broader monitoring programme it feeds
  • Rules extend existing anti-money-laundering law to crypto businesses
  • FATF sets the global standards; national bodies like FinCEN enforce them
  • The Travel Rule sends sender and recipient data between regulated firms
  • Obligations fall on intermediaries, not on individuals holding their own assets

KYC (“Know Your Customer”) and AML (“Anti-Money Laundering”) are the identity checks and monitoring rules that regulated crypto businesses must run to keep criminals out of the financial system. KYC is the step where a platform verifies who you are; AML is the broader programme that KYC feeds into, covering ongoing monitoring, record-keeping and reporting of suspicious activity. This article explains what these obligations are, why exchanges ask for your documents, and how the rules fit together.

This is a general explainer. The specific obligations, thresholds and documents differ by jurisdiction, so treat the examples here as illustrations rather than the exact rules that apply to you.

What AML is trying to stop

Anti-money-laundering law exists to make it hard to disguise the proceeds of crime as legitimate funds, and to cut off financing for terrorism and sanctions evasion. It predates crypto by decades: the United States Bank Secrecy Act, for instance, has long required financial institutions to keep records and report certain transactions. As crypto grew, regulators extended these existing frameworks to cover businesses that deal in virtual assets, rather than writing entirely new ones.

The global anchor is the Financial Action Task Force (FATF), an intergovernmental body that sets AML standards its member countries then translate into national law. FATF’s recommendations treat crypto exchanges and similar firms as “Virtual Asset Service Providers” (VASPs) and expect them to meet broadly the same obligations as banks.

KYC: verifying who you are

KYC is the customer-identification part of an AML programme. When you open an account on a regulated exchange, it typically collects and checks:

  • Identity, using government-issued documents such as a passport or driving licence.
  • Proof of address, often a utility bill or bank statement.
  • A liveness or selfie check, to confirm the document belongs to the person presenting it.
  • Risk information, such as source of funds for larger accounts.

This is sometimes called Customer Due Diligence (CDD). For higher-risk customers, firms apply Enhanced Due Diligence (EDD), which means deeper checks and closer ongoing scrutiny. The goal is not bureaucracy for its own sake: it establishes a verified identity behind an account so that later monitoring means something.

From KYC to ongoing monitoring

Verifying identity once is only the start. A full AML programme continues after onboarding and generally includes:

  • Transaction monitoring to flag patterns that look like layering, structuring or other laundering techniques.
  • Sanctions and watchlist screening against lists maintained by governments.
  • Record-keeping so that identity and transaction data can be produced if authorities request it.
  • Suspicious Activity Reports (SARs), filed with the national financial-intelligence unit when something looks wrong.

In the United States, FinCEN (the Financial Crimes Enforcement Network) administers much of this and has published guidance clarifying that money-transmission rules apply to many crypto businesses. Firms are expected to appoint a compliance officer, train staff and keep the programme current.

The Travel Rule

One crypto-specific obligation deserves its own section because it often surprises users. FATF’s Recommendation 16, widely called the “Travel Rule”, requires that when value above a set threshold moves between VASPs, certain originator and beneficiary information “travels” with the transfer, much as it does for a bank wire. The threshold FATF recommends is 1,000 USD or EUR, though countries implement it differently.

In practice this means a regulated exchange sending crypto to another regulated exchange may share the sender’s and recipient’s identifying details behind the scenes. It is a compliance data exchange between institutions, not something that alters the on-chain transaction itself. Understanding it helps explain why regulated platforms sometimes ask where a withdrawal is going.

A risk-based approach, not one-size-fits-all

Modern AML frameworks are described as “risk-based”, which means firms are expected to scale their scrutiny to the risk a customer or transaction presents rather than treating everyone identically. A small retail account funded from a local bank sits at one end; a high-value account with funds routed through several jurisdictions sits at the other, and attracts far closer attention. This is why two people can have very different onboarding experiences on the same platform, and why a previously quiet account can suddenly trigger questions when its behaviour changes.

The risk-based idea also explains why compliance is never truly “finished”. Firms periodically re-verify customers, refresh their understanding of who they are dealing with, and re-screen against updated sanctions lists. A platform asking you to confirm details you provided a year ago is usually performing this ongoing review, not singling you out.

Why custody type changes the picture

KYC and AML obligations attach to businesses that hold or exchange assets on behalf of others. That is why a custodial platform, which controls your keys, runs full identity checks, while using self-custodial software where you alone hold the keys generally does not put you through KYC at all. The distinction matters: the law targets intermediaries, so the more an intermediary is involved, the more identity and monitoring you should expect. This is also why the same person can face heavy verification on an exchange and none when moving funds between their own wallets.

What it means for you as a user

For an ordinary, honest user, KYC and AML mostly show up as onboarding friction and the occasional query about a transaction. A few practical points help set expectations:

  • Regulated platforms are legally required to verify you; refusing all identity checks usually means you cannot use them, by design.
  • Providing accurate information matters, because mismatches can freeze access while a firm investigates.
  • Your data is retained for years under record-keeping rules, so consider a platform’s security and privacy practices before signing up.
  • Large or unusual transfers may prompt questions about source of funds; this is routine compliance, not an accusation.

None of this is a comment on any individual’s risk. It is simply how the system is built to function.

Who these rules actually bind

A common source of confusion is who the law is aimed at. AML obligations fall on businesses that provide financial services, not on individuals simply for owning or moving their own assets. The exchange, broker or custodian is the “obliged entity” that must build a compliance programme, verify customers and file reports. You experience the rules as a customer of such a firm, but you are not the one legally required to run KYC. This is why the same activity conducted through a regulated intermediary triggers checks, while activity that involves no such intermediary generally does not, a distinction that also underpins how different custody models are treated.

Common misunderstandings

A few myths are worth clearing up. KYC is not the same as your money being safe: identity verification does nothing to protect you from a platform’s insolvency or hack, which is a separate risk. AML rules do not make crypto “anonymous by default”; regulated on-ramps and off-ramps link identities to activity, and blockchains themselves are usually public and traceable. And meeting KYC on one platform does not carry over to another, because each regulated firm must run its own checks.

Bottom line

KYC and AML are the identity and monitoring backbone that lets regulated crypto businesses operate legally. KYC verifies who you are; AML uses that verified identity for ongoing monitoring, sanctions screening and reporting, coordinated internationally through FATF and enforced nationally by bodies such as FinCEN. The rules apply to intermediaries, which is why custodial services check you thoroughly and self-custody generally does not. Exactly which checks, thresholds and reports apply depends on your jurisdiction, so verify the current requirements with the relevant regulator or a qualified professional.

Sources

  1. FATF Virtual Assets and VASPs
  2. FinCEN Guidance
  3. HMRC Cryptoassets Manual (gov.uk)

Frequently asked questions

What is the difference between KYC and AML?

KYC is the identity-verification step where a platform confirms who you are. AML is the wider programme that KYC feeds into, covering ongoing monitoring, record-keeping, sanctions screening and reporting of suspicious activity.

Why does a crypto exchange need my ID?

Because regulated exchanges are legally treated like other financial institutions and must verify customers under anti-money-laundering law. The exact documents and thresholds differ by jurisdiction.

What is the crypto Travel Rule?

It is FATF Recommendation 16, which requires identifying information about the sender and recipient to accompany transfers above a set threshold between regulated service providers, similar to a bank wire.

Last reviewed: 26 Aug 2026 Next review: 26 Feb 2027 Section: Crypto
Liam Chen
Protocol & security writer · Blockchain mechanics, wallet security, cryptography

Liam Chen writes about how crypto works at the protocol level — consensus, cryptography, wallets and security. He explains mechanisms plainly and cites primary sources.

More by Liam Chen

Related

Crypto

How crypto phishing attacks actually work

How crypto phishing attacks work: the tricks that steal wallets, the wallet-drainer signature scam, and the simple habits that stop…

Liam Chen · Aug 26, 2026 · 6 min
Crypto

What is a Merkle tree?

A Merkle tree summarises many items into one hash. Learn what a Merkle tree is, how it is built from…

Liam Chen · Aug 26, 2026 · 5 min