Know Your Customer (KYC) is the regulated obligation requiring a digital-asset business to identify, verify, and understand each client before providing services – and to keep that understanding current throughout the relationship. The requirement flows primarily from FATF Recommendation 10 and the national laws that transpose it, including the anti-money-laundering directives operative across EU member states under the MiCA (Markets in Crypto-Assets Regulation) perimeter, the rulebooks issued by VARA (Virtual Assets Regulatory Authority) in Dubai, the Payment Services Act regime administered by MAS in Singapore, and parallel regimes from the FCA in the UK to FINMA in Switzerland. For a digital-asset business, KYC is not a back-office formality. It is the foundation on which a licence stands – and the first thing a regulator checks when something goes wrong.
With supervisory expectations tightening across every major hub, the cost of an inadequate KYC program now extends beyond a compliance fine. Banks pull rails. Regulators suspend licences. Counterparties in institutional markets run their own due diligence on your controls before they deal. This guide sets out the legal basis, the practical architecture, and the cross-border realities that every digital-asset operator needs to understand before going live – or before the next regulatory review.
What Does KYC Actually Mean for a Crypto Business?
KYC for a crypto business is the three-part obligation to identify the customer, verify that identity against reliable independent sources, and maintain an ongoing understanding of the customer's purpose, expected activity, and risk profile. It is part of a wider Customer Due Diligence (CDD) obligation, which also covers the identification of ultimate beneficial owners and, in higher-risk cases, the enhanced measures known as Enhanced Due Diligence (EDD).
The legal basis is the FATF Recommendation 15 standard for virtual asset service providers (VASPs) – the umbrella category that covers exchanges, custodians, brokers, transfer services, and increasingly DeFi-adjacent platforms. Every major licensing regime for digital assets incorporates these standards by reference or by direct drafting. Under MiCA, a CASP (crypto-asset service provider) authorised in one EU member state must comply with the applicable AML directive – and the CASP passport that opens the rest of the EU market is conditional on that compliance. A weak KYC program is, therefore, a passport problem, not just a compliance issue.
In our cross-border practice, we regularly advise clients who confuse registration with compliance. A VASP registration granted in a given jurisdiction confirms that the regulator has seen the business's AML policies. It does not certify that those policies work. The test comes at the supervisory review – typically an on-site or desktop examination of real customer files, real onboarding flows, and real monitoring alerts.
The KYC obligation is continuous, not a one-time check at account opening. Periodic refresh, event-triggered review (for example, when a customer's transaction pattern changes materially), and ongoing screening against sanctions lists are all part of the standard. Regulators in the leading hubs increasingly expect automated and documented workflows, not manual processes that depend on a single compliance officer's memory.
What Is the Regulatory Basis Across the Major Licensing Regimes?
The regulatory basis for crypto KYC is the FATF standards as implemented in the licensing framework of each jurisdiction – and while the core obligations align, the operational details diverge in ways that create real cost and risk for cross-border operators. Understanding those divergences before you select a jurisdiction is essential.
Under MiCA and the applicable EU AML framework, a CASP must apply CDD to all customers, with risk-stratified procedures determining the depth of that due diligence. The EU's AML package (the set of instruments that accompanies MiCA) moves toward a single AML authority at the EU level, which will bring more uniform supervisory intensity across member states. For businesses that chose an EU base partly because a given national regulator was perceived as lighter-touch, that calculation is shifting.
In Dubai, VARA's rulebooks impose AML and KYC obligations as a condition of each activity-based licence. The VARA regime covers mainland Dubai (outside the DIFC financial free zone) and requires that licensed VASPs maintain policies, procedures, and controls that meet VARA's standards – including customer identification, beneficial ownership verification, and transaction monitoring. VARA's supervisory posture has grown materially more active since the regime's initial roll-out, and operators we advise report increasingly detailed examination of onboarding flows during supervisory visits.
MAS in Singapore administers KYC obligations for Digital Payment Token service providers under the Payment Services Act. The MAS AML notices set out detailed requirements for customer identification, EDD triggers, and the politically exposed persons (PEP) screening that operators must embed in their onboarding. Singapore's regime is widely regarded as technically rigorous, and MAS has shown willingness to refuse or revoke licences where AML controls do not meet its expectations.
In the UK, the FCA's cryptoasset registration under the Money Laundering Regulations is the gateway for firms operating in or from the UK. The FCA has been explicit that weak KYC is a primary reason for registration refusals – and firms that operate without registration while serving UK customers expose themselves to criminal liability, not merely a regulatory sanction. The FCA's financial-promotion rules add a further dimension: marketing crypto to UK consumers is separately regulated, and an unlicensed firm that also runs inadequate KYC is accumulating enforcement risk from multiple directions.
FINMA in Switzerland applies its AML and KYC standards to VASPs via the banking law, the fintech licence pathway, and the self-regulatory organisation (SRO) affiliation requirement. Swiss practice demands thorough documentation of beneficial ownership – a standard that has been tested in cross-border enforcement cooperation where Swiss-licensed entities received correspondent requests from other jurisdictions.
For a business operating across multiple markets, the structural question is which regime sets the floor for the group. In our practice, we map the licence stack – operating entity, custody layer, and payment rails – against the most demanding KYC standard the group faces, and we build the compliance architecture to that standard. Adopting the lowest common denominator is a risk that surfaces at the worst possible moment.
CTA #1
The process above describes the standard architecture. Your facts – the entity structure, the user base geography, the banking counterparties – change the analysis materially. For a scoped assessment of your KYC obligations across the jurisdictions where you operate, contact OBOLUS at Map your options.
How Does KYC Connect to the Travel Rule?
The Travel Rule (the obligation under FATF Recommendation 16 to pass originator and beneficiary data with a virtual-asset transfer) is, in practice, an extension of KYC – because you cannot pass accurate identifying information about a sender or recipient if you have not verified that information in the first place. A VASP with weak KYC will inevitably produce Travel Rule outputs that are incomplete, inaccurate, or fabricated, any of which exposes the firm to sanctions-evasion liability as well as AML enforcement.
The operational challenge is matching. When your customer sends funds to another VASP, the Travel Rule requires that VASP to verify the data you send against its own customer records. If your KYC has identified a customer by one version of a name and the receiving VASP has a different version, the transfer may be flagged or rejected. This is not a technical glitch. It is a KYC-quality problem that creates friction at the transaction level and, at scale, generates compliance alerts that both sides must investigate.
Under MiCA and the EU's Transfer of Funds Regulation (TFR) as it applies to crypto-assets, the threshold-based and universal requirements for Travel Rule data mean that a CASP must have its KYC records in a format that can be extracted and transmitted consistently across the major inter-VASP messaging protocols. Regulators increasingly assess Travel Rule readiness as part of the same examination that covers KYC program quality.
A recent matter in our practice illustrates the interaction. A payment-facing exchange had built a compliant onboarding flow for its direct customers but had not designed its KYC data structure to feed its Travel Rule messaging system. The result was manual extraction for every cross-VASP transfer – a process that introduced errors and delays that VARA flagged during a supervisory review. The remediation required a rebuild of the data architecture, not just a policy update. The lesson: KYC and the Travel Rule must be designed together from the outset.
When Does Enhanced Due Diligence Apply – and What Does It Require?
Enhanced Due Diligence applies when the assessed risk of a customer or transaction exceeds the threshold at which standard CDD is adequate – and for digital-asset businesses, those triggers are more frequent than in traditional finance because of the pseudonymous nature of on-chain activity, the global user base, and the speed of settlement. EDD is not optional when a trigger condition is present. It is a legal obligation, and failure to apply it is the most commonly cited deficiency in regulatory enforcement actions against VASPs.
The principal EDD triggers across major regimes include: customers classified as politically exposed persons (PEPs) or their close associates; customers from high-risk or sanctioned jurisdictions identified on FATF's public lists; business relationships with complex or opaque ownership structures; and customers whose transaction patterns deviate materially from the stated purpose of the account. In practice, the last category – behavioral triggers – is the most operationally demanding, because it requires active transaction monitoring that feeds back into the KYC file.
EDD in a digital-asset context typically involves obtaining source-of-funds documentation (not merely a self-certification), independent verification of ownership claims, enhanced sanctions screening, and a senior management sign-off before the relationship proceeds. The documentation must be contemporaneous. A regulator reviewing a file two years after onboarding will look for records that were created at the time of the decision, not reconstructed afterward.
For businesses serving institutional counterparties – funds, family offices, corporate treasuries – EDD often involves analysis of the counterparty's own AML program. This is sometimes called correspondent-style due diligence. The VARA regime, MAS, and MiCA-aligned NCAs all permit risk-based reliance on third-party due diligence, subject to documented conditions. But the liability for the KYC decision remains with the licensed entity. Outsourcing the work does not outsource the regulatory exposure.
What Are the Cross-Border KYC Challenges for a Multi-Jurisdiction Operator?
Operating a digital-asset business across multiple jurisdictions means managing KYC obligations that are similar in structure but divergent in detail – and the divergence matters most at the edges, where high-risk customers, politically sensitive relationships, and complex ownership structures sit. For a cross-border operator, those edges are also the highest-revenue segments of the business.
The first challenge is data. KYC requires collecting personal information about customers, and personal information is regulated differently across jurisdictions. The EU's General Data Protection Regulation imposes obligations on how customer data is stored, transferred, and retained that interact directly with AML record-keeping requirements. A CASP authorised in an EU member state that also operates from a Dubai entity must design its data architecture to satisfy both regimes – and they do not always point in the same direction.
The second challenge is the PEP list. PEP definitions vary. A person who is classified as a PEP under one national framework may not be classified the same way under another. For an exchange with users across dozens of countries, maintaining an accurate, current, and jurisdiction-specific PEP screening process at scale requires either a commercially licensed database or a substantial internal compliance capability – or both.
The third challenge is the unhosted wallet. Transfers to and from wallets not held at a regulated VASP – sometimes called self-hosted wallets – create a KYC gap. The customer's identity is known; the counterparty's is not. Under the TFR and analogous regimes, VASPs must take risk-based measures to address that gap. In practice, this involves a combination of chain analysis, customer self-declaration, and, for higher-value transfers, independent forensic verification. The threshold at which these measures are required varies by jurisdiction – and that variation is itself a compliance variable that cross-border operators must track.
We have seen businesses design excellent KYC programs for their primary licensing jurisdiction and then discover – typically when a second regulator asks – that the same program does not meet the standards of the market where most of their revenue sits. Building the compliance architecture to the most demanding applicable standard from the outset is materially cheaper than remediation.
CTA #2
If a prior compliance program was built for one jurisdiction and you are now facing scrutiny from a second, a structural gap analysis can identify the exposure before the regulator does. Write to OBOLUS at Map your options – we regularly advise on cross-border KYC remediation.
Who Is Responsible for KYC Inside the Business – and What Does the MLRO Do?
The Money Laundering Reporting Officer (MLRO) – sometimes titled Compliance Officer or AML Officer depending on the jurisdiction – is the individual within the licensed entity who holds personal regulatory responsibility for the KYC and AML program. The MLRO is not simply a policy writer. The role carries legal exposure: an MLRO who signs off on a deficient program, approves a high-risk relationship without adequate EDD, or fails to file a suspicious activity report when the facts require it can face personal regulatory sanction and, in the most serious cases, criminal liability.
Regulatory expectations for the MLRO have risen significantly across all the major regimes. VARA, MAS, the FCA, and MiCA-aligned NCAs now expect the MLRO to be a senior, experienced individual with genuine authority within the business – not a nominal appointment. The regulator will ask whether the MLRO has access to transaction data, whether they can override a business decision on AML grounds, and whether they report directly to the board. Answers that reveal the MLRO as a compliance box-tick rather than a functioning control are a red flag in any supervisory examination.
For smaller businesses and startups, the cost of a qualified MLRO has pushed many toward outsourced compliance functions. This is permitted by most regimes, subject to conditions. The licensed entity must retain ultimate responsibility, the outsourced function must be contractually bound to the same standards, and the arrangement must be documented and disclosed to the regulator. An outsourced MLRO who operates as a genuine senior advisor to the business is very different from a service provider who produces policies but has no real-time visibility into the business's operations – and regulators are increasingly alert to the difference.
How Does Transaction Monitoring Work in a Crypto KYC Program?
Transaction monitoring is the ongoing surveillance of customer activity against expected patterns and risk indicators – and in a digital-asset business, it operates on two levels simultaneously: the account level (fiat or custody balances, deposit and withdrawal patterns) and the on-chain level (the blockchain addresses associated with the customer and the history of those addresses). The on-chain dimension is what makes crypto transaction monitoring both more powerful and more complex than its traditional-finance equivalent.
On the account level, the program uses rules and models to flag transactions that deviate from the customer's risk profile: a sudden large deposit from a new counterparty, a rapid conversion and withdrawal, a pattern of transactions just below a reporting threshold. These flags generate alerts that the compliance team must review, investigate, and either resolve or escalate to a Suspicious Activity Report (SAR) or equivalent filing.
On the on-chain level, forensic tools – Chainalysis, TRM Labs, Elliptic, and Asset Reality are established providers in this category – allow a VASP to trace the history of funds arriving into a customer's account and to assess the risk profile of those funds against known categories: sanctioned addresses, darknet market exposure, mixing services, high-risk exchanges. Chainalysis and TRM Labs are among the widely used chain-analysis providers in regulated VASP programs. The output of that analysis feeds the customer's risk score and can trigger EDD or, in extreme cases, an SAR filing and account exit.
The integration challenge is real. Many VASPs run their account-level monitoring in a traditional financial crime tool and their chain analysis in a separate platform, and the two systems do not always communicate. A customer who passes the account-level rules may show unacceptable on-chain risk that only surfaces in the forensics tool – and if the two outputs are not reconciled, the compliance decision is based on incomplete information. Regulators are beginning to examine this integration as a specific technical control, not just a general compliance question.
Operators we advise are increasingly designing unified risk-scoring architectures that ingest both data streams into a single customer risk file. The investment is non-trivial, but the alternative – parallel systems that can produce contradictory assessments – is a supervisory liability.
How Does a Deficient KYC Program Affect a Licence Application or Renewal?
A deficient KYC program is one of the most common reasons a digital-asset licence application is refused, delayed, or granted with conditions – and it is also the most common trigger for licence suspension or revocation after authorisation. The reason is structural: the KYC program is evidence of the business's fitness to hold a licence. A regulator reviewing an application is, in part, reviewing whether the applicant can be trusted to prevent its platform from being used for money laundering, sanctions evasion, or terrorism financing. The KYC documentation is the primary evidence on which that assessment rests.
In the EU, under MiCA and the applicable AML framework, a CASP application requires the submission of detailed AML policies and procedures, a description of the KYC process flow, the risk assessment methodology, and evidence that the MLRO meets the competence and seniority requirements. An application that submits generic template policies without evidence of implementation – the systems, the staffing, the escalation procedures – will not pass. We have seen licensing timelines extend by months because an applicant's compliance documentation was structurally complete but operationally thin.
Under VARA's regime, the supervisory review of compliance controls is embedded in both the initial authorisation process and in ongoing supervision. A VARA-licensed exchange that experiences a compliance failure – a major SAR filing gap, an onboarding failure that allowed a sanctioned party to transact – will face a supervisory action that can include mandatory remediation, additional conditions, and in serious cases suspension. The licence is never a permanent grant. It is a conditional permission that the regulator can modify or withdraw.
The practical implication for any business planning a licence application is that the KYC program must be built and operational – not just documented as a future plan – before the application is submitted. Regulators are increasingly asking for evidence of real implementation: staff training records, sample case files, audit logs from the monitoring system. A program that exists only in a policy manual is not a program.
What Are the Most Common KYC Failures in Digital-Asset Businesses?
The most common KYC failures we see in practice fall into a small number of recurring patterns. Each is avoidable with disciplined program design – but each also tends to surface only when a regulator or counterparty looks closely, which is often too late for a low-cost fix.
Onboarding without ongoing monitoring. The business invests in a strong initial CDD process and then does not maintain it. Customer risk profiles are never refreshed, sanctions screening runs on the original onboarding data rather than a live feed, and the KYC file diverges from the current reality of the customer relationship. This is the most common gap in smaller and mid-size VASPs, and it is the gap that most often produces regulatory enforcement action after a compliance event.
Reliance on self-certification for beneficial ownership. A business accepts a customer's own statement about its ownership structure without independent verification. Under every major regime, beneficial ownership verification requires documentation from reliable independent sources – corporate registries, notarised certificates, audited accounts. A self-certification is evidence of what the customer says. It is not verification of what is true.
One-size-fits-all risk profiling. Applying the same CDD procedure to every customer regardless of risk profile is a compliance failure, not a conservative approach. Regulators expect risk stratification: a straightforward retail customer onboarded from a low-risk jurisdiction with a low-value expected activity profile warrants standard CDD. A corporate customer from a high-risk jurisdiction with a complex ownership structure warrants EDD. Applying EDD to everyone is operationally inefficient and does not demonstrate a risk-based approach. Applying standard CDD to everyone is a regulatory violation.
Treating KYC as a legal department function rather than a business-wide obligation. KYC works only if the people making commercial decisions – the relationship managers, the business development team, the product leads – understand their obligations and escalate appropriately. A compliance program that lives only in the legal team and has no real-time connection to the business's commercial activity will always have blind spots. The MLRO must be embedded, not isolated.
A common assumption in the market is that a single offshore registration or a light-touch registration in a permissive jurisdiction is sufficient to serve clients globally with minimal KYC requirements. That is not the legal position. The applicable KYC standard is determined by where you are licensed, where your customers are, where your banking sits, and – increasingly – where the relevant regulators have extraterritorial reach. Operating on the assumption that a single offshore licence creates a compliant global business is a structural risk that surfaces in enforcement, not in routine supervision.
Related at OBOLUS
Related at OBOLUS
- Compliance, AML & Travel Rule Practice – full-service AML program design, MLRO support, and regulatory examination preparation across major hubs.
- Travel Rule Compliance: Practical Lessons for Boards – board-level analysis of Travel Rule implementation, inter-VASP messaging, and data architecture decisions.
- Smart Contract Dispute Resolution in Liechtenstein – how Liechtenstein's legal regime addresses smart-contract disputes and on-chain enforcement questions.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 16 – requires a VASP originating a virtual-asset transfer to pass identifying information about the sender and the intended recipient to the beneficiary VASP before or at the time of the transfer. The data must include name, account details, and, in most implementations, address or other identifying information. The receiving VASP must verify the beneficiary data against its own KYC records. Thresholds vary by jurisdiction; consult current legislation for the applicable de minimis in your operating market.
Who must act as MLRO for a crypto firm?
Most licensing regimes require the MLRO to be a sufficiently senior and experienced individual who holds genuine authority within the firm – including the ability to halt a business relationship on AML grounds and to report directly to the board. The person must be approved or at least assessed by the relevant regulator as part of the licensing process. Outsourced MLRO arrangements are permitted in many jurisdictions, subject to documented oversight, but the licensed entity retains legal responsibility for the program's effectiveness.
How do regulators audit crypto AML programs?
Regulators typically audit a crypto AML program through a combination of desktop review (policy documents, risk assessments, training records, SAR filing statistics) and file-based examination (a sample of actual customer onboarding files, monitoring alert logs, and EDD cases). On-site visits may include interviews with the MLRO and compliance staff. Regulators increasingly examine the technical integration between account-level monitoring and on-chain analytics. A program that looks complete on paper but lacks documented operational evidence of implementation will not pass.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, KYC, and compliance architecture that sits around every regulated digital-asset operation. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking, and compliance stack across operating, custody, and payment layers before you commit – because the cost of building to the wrong standard is always higher than the cost of getting it right the first time. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-border KYC architecture, VASP AML program design, and regulatory examination preparation across the EU, UAE, Singapore, and UK licensing regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.