Crypto news and analysis
Intermediate · Regulation

Anti-money-laundering rules in crypto

Understand crypto AML programs through risk assessment, transaction monitoring, sanctions controls, Travel Rule data, reporting, and governance.

13 min read3-question quizUp to 205 XP

Anti-money-laundering and counter-terrorist-financing rules aim to detect, deter, and report misuse of financial services. In crypto, they can apply to exchanges, custodians, brokers, transmitters, and other covered providers depending on local definitions. The public ledger changes available evidence but does not replace customer understanding or case investigation.

An effective program connects customer risk, transaction behavior, sanctions controls, blockchain evidence, escalation, reporting, and recordkeeping. No single risk score proves criminal conduct, and an alert becomes useful only when investigators can test it against reliable context and document a defensible disposition.

What you will learn

  • Build an AML program from risk assessment through independent testing
  • Explain monitoring, alert investigation, and suspicious-activity reporting
  • Describe Travel Rule data and counterparty-provider controls
  • Balance financial-crime detection with privacy, accuracy, and access

Start with obligations and risk

A covered business first determines its legal status in each jurisdiction, including registration or licensing and the identity of its supervisor. In the United States, FinCEN's May 9, 2019 guidance applies Bank Secrecy Act regulations to specified convertible virtual-currency business models and emphasizes activity over labels. State and other federal obligations can apply separately.

The enterprise risk assessment examines customers, products, assets, delivery channels, counterparties, and geographies. It should use internal data, authoritative threat information, incidents, law-enforcement feedback, and control results. The output drives policies, staffing, systems, training, monitoring, and testing rather than serving as a static document produced for an examination.

Monitoring and investigation

Transaction monitoring combines customer profile, account behavior, fiat flows, device information, counterparties, and blockchain analytics where lawful and relevant. Scenarios can identify rapid movement, structuring, unusual exposure, account takeover, fraud proceeds, sanctions indicators, mixers, or behavior inconsistent with the stated purpose. An alert is a question, not a finding of crime.

Investigators validate data, review context, trace funds, compare prior behavior, seek information where permitted, and record a reasoned decision. Escalated cases may lead to restrictions, enhanced monitoring, suspicious-activity reporting, or other action under governing law. Filing thresholds, confidentiality, timelines, and tipping-off restrictions differ, so global firms need jurisdiction-specific procedures.

Travel Rule information

FATF Recommendation 16 extends originator and beneficiary information principles to qualifying virtual-asset transfers through covered providers. The EU's Regulation 2023/1113, applicable from December 30, 2024, sets directly applicable transfer-information rules for covered crypto-asset service providers. National thresholds, required fields, self-hosted-address treatment, and implementation details are not globally uniform.

Compliance requires identifying the counterparty provider, securely transmitting required information, checking completeness, protecting data, handling unsupported counterparties, and retaining records. The information need not be embedded in a public blockchain transaction. Interoperability failures, mismatched names, privacy restrictions, and providers in jurisdictions without equivalent implementation create operational decisions that policies must address.

Governance, testing, and tradeoffs

An effective program needs accountable leadership, a sufficiently independent compliance function, trained staff, reliable data, documented model changes, quality assurance, and independent testing. Metrics should include alert quality, aging, repeat issues, reporting timeliness, data gaps, false positives, customer harm, and remediation, not simply the number of accounts closed or reports filed.

AML controls create policy tradeoffs. Intensive surveillance may improve detection while increasing privacy intrusion, data-security exposure, exclusion, and mistaken restrictions. Weak controls can enable fraud, corruption, sanctions evasion, and terrorist financing. Proportionality, legal purpose, explainable decisions, correction mechanisms, and outcome testing help manage the tension without claiming perfect prevention.

Reality check

Common misconceptions

AML rules apply only after a customer is proven to be a criminal.

AML programs assess risk, monitor behavior, and report qualifying suspicion without requiring the institution to prove a criminal offense. Authorities determine further action.

Blockchain analytics automatically proves who controls an address and why funds moved.

Analytics estimates links and risk using available data. Attribution, ownership, intent, and context can remain uncertain and require corroboration.

The FATF Travel Rule has identical fields and thresholds everywhere.

FATF sets international standards, but countries enact and enforce them through local law, producing timing, scope, threshold, and procedural differences.

Before you act

Risks and limitations

  • False positives can freeze or close legitimate accounts, while false negatives allow harmful activity to continue undetected.
  • Analytics and vendor risk includes opaque attribution, stale labels, concentration, outages, and inappropriate reliance on probabilistic scores.
  • Privacy risk grows when identity, counterparties, devices, and transaction histories are aggregated or transmitted across borders.
  • Fragmented Travel Rule implementation can cause rejected transfers, data leakage, inconsistent treatment, and regulatory gaps.

Key takeaways

  1. Determine covered status and jurisdiction before designing the AML program.
  2. Treat alerts and analytics as investigative leads, not proof of guilt.
  3. Separate sanctions prohibitions from suspicious-activity analysis while coordinating controls.
  4. Implement Travel Rule duties according to applicable local law and secure data handling.
  5. Measure detection quality, timeliness, data gaps, and customer harm through independent testing.

Primary and further reading

Knowledge check

Test your understanding

Score at least 2 out of 3 to complete this lesson. Explanations appear after you submit.

1. What does a transaction-monitoring alert establish?
2. Why are sanctions screening and AML monitoring not interchangeable?
3. What is a sound use of blockchain analytics?