Aml Requirements

 Definition

AML requirements are the specific, enforceable obligations that governments and regulators impose on financial institutions, cryptocurrency exchanges, virtual asset service providers (VASPs), and other regulated entities to prevent and detect money laundering and the financing of terrorism. While AML regulations establish the legal framework, AML requirements are the granular operational duties that flow from those regulations – the concrete things a business must actually do. Core requirements typically include: establishing a written AML compliance programme; appointing a Money Laundering Reporting Officer (MLRO); conducting customer identification and Know Your Customer (KYC) checks before onboarding; performing Customer Due Diligence (CDD) and, for higher-risk customers, Enhanced Due Diligence (EDD); monitoring transactions continuously for suspicious patterns; filing Suspicious Activity Reports (SARs) within mandated deadlines; retaining customer and transaction records for a minimum period (typically five years); applying the FATF Travel Rule for cross-border virtual-asset transfers; screening customers and transactions against sanctions lists; and training all relevant staff. In the crypto context, FATF’s 2019 guidance and national implementing rules mean that exchanges and custodians face essentially the same operational checklist as traditional banks, covering everything from the first customer interaction to ongoing lifecycle monitoring and exit procedures for high-risk accounts.

 Origin & History

DateEvent
1970US Bank Secrecy Act establishes the first formal AML requirements: record-keeping and large-cash reporting for financial institutions
1990FATF 40 Recommendations define the core requirements that national regulators must translate into law: CDD, record-keeping, reporting, and international cooperation
1992US Annunzio-Wylie Act adds SAR filing as a mandatory requirement for US banks
2001USA PATRIOT Act introduces formal Customer Identification Programme (CIP) requirements, mandating identity verification for new accounts
2003FATF revises recommendations to include Politically Exposed Persons (PEP) screening and enhanced due diligence as explicit requirements
2016US FinCEN Customer Due Diligence (CDD) Rule finalised, adding beneficial ownership identification as a mandatory requirement for legal entity customers
2016FATF adopts the Travel Rule (Recommendation 16) as a formal requirement for financial institutions; extended to VASPs in 2019
2019FATF Interpretive Note to Recommendation 15 imposes full VASP AML requirements on crypto exchanges; FinCEN reaffirms BSA obligations for virtual-asset businesses
2021US Anti-Money Laundering Act strengthens requirements, mandating a national AML priorities list and updating beneficial-ownership rules
2024US Corporate Transparency Act (CTA) Beneficial Ownership Information (BOI) reporting requirements come into effect for millions of US entities

“VASPs should be required to implement the full suite of AML/CFT requirements equivalent to those required of other financial institutions – including CDD, record-keeping, suspicious transaction reporting, and compliance with the Travel Rule.” – FATF Guidance for a Risk-Based Approach to Virtual Assets, 2021

 How It Works

ENTITY SUBJECT TO AML REQUIREMENTS │ ┌─────────┴──────────┐ │  Written AML        │ │  Compliance         │ │  Programme          │ └─────────┬──────────┘ │ implemented through ┌──────────┼──────────────────────────┐ │          │                          │ ▼          ▼                          ▼ KYC / CDD  Transaction              Record- Programme  Monitoring               Keeping │          │                          │ ▼          ▼                          ▼ Customer   SAR / STR Filing         5-Year ID + EDD   to FIU                   Retention │          │                          │ └──────────┴──────────────────────────┘ │ ▼ TRAVEL RULE (VASP-to-VASP data sharing on transfers above threshold) │ ▼ SANCTIONS SCREENING (OFAC, UN, EU lists) │ ▼ STAFF TRAINING (annual minimum) “`

RequirementTraditional BankCrypto Exchange (VASP)
KYC / CIPMandatory (PATRIOT Act)Mandatory (FinCEN 2019 guidance)
Customer Due DiligenceMandatory (CDD Rule 2016)Mandatory (FATF R.10)
Enhanced Due DiligenceFor high-risk customersFor high-risk customers / high-value wallets
Transaction MonitoringMandatoryMandatory + on-chain analytics recommended
SAR FilingMandatory (30-day deadline)Mandatory (30-day deadline)
Travel RuleMandatory for wire transfersMandatory for VA transfers ≥$3,000 (US)
Sanctions ScreeningOFAC mandatoryOFAC mandatory; SDN list screening
Record Retention5 years minimum5 years minimum
Annual Staff TrainingMandatoryMandatory
MLRO / Compliance OfficerMandatoryMandatory

 In Simple Terms

  1. KYC is the entry gate – before opening an account or allowing significant trading, the exchange or bank must verify who the customer is, using government-issued ID, proof of address, and, for businesses, beneficial-ownership information.
  2. CDD and EDD calibrate the depth of scrutiny – standard customers receive basic due diligence; politically exposed persons, high-value accounts, or customers from high-risk jurisdictions receive enhanced due diligence with more thorough background checks.
  3. Transaction monitoring never stops – automated systems watch every transaction for red flags (structuring, rapid cycling, high-risk counterparties), generating alerts that compliance analysts review and escalate if necessary.
  4. The Travel Rule follows the money – when crypto moves between VASPs, both sides must share originator and beneficiary identity data above the applicable threshold, mirroring the wire-transfer rules that have applied to banks for decades.
  5. Record-keeping creates accountability – all KYC documents, transaction records, and SAR filings must be retained for at least five years, enabling regulators and law enforcement to audit compliance and reconstruct suspicious transactions.

 Real-World Examples

ScenarioImplementationOutcome
New user onboards at crypto exchangeExchange collects government ID, selfie, proof of address; screens against PEP and sanctions lists; assigns risk ratingLow-risk user cleared in minutes via automated KYC; high-risk user routed to manual EDD review
High-volume trader triggers EDDCustomer’s monthly trading volume exceeds internal threshold; source-of-wealth documentation requestedCustomer provides salary slips and investment statements; MLRO approves continuation; record retained for 5 years
Cross-border crypto transfer above thresholdSending VASP shares originator name, address, and wallet with receiving VASP per FATF Travel RuleReceiving VASP screens data, clears transfer; compliance documented; Travel Rule obligations met in both jurisdictions
Compliance audit by regulatorRegulator requests five years of KYC records and SAR filing logsExchange produces complete records from secure document management system; no deficiencies found; no penalty issued

 Advantages

AdvantageDescription
Creates a level playing fieldUniform AML requirements prevent a race to the bottom where tax-compliance operators undercut compliant firms
Protects the institutionMeeting requirements shields firms from regulatory penalties, reputational damage, and criminal liability
Enables market accessMany institutional partners and payment processors require counterparties to demonstrate AML compliance before onboarding
Strengthens customer trustCustomers – particularly institutional clients – are more likely to transact with exchanges that can demonstrate strong AML controls
Supports global interoperabilityStandardised requirements (especially the Travel Rule) enable smooth, compliant cross-border crypto transactions
Reduces insider riskMandatory staff training and clear escalation paths reduce the chance that employees unwittingly or deliberately assist money laundering

 Disadvantages & Risks

RiskDescription
High implementation costBuilding KYC infrastructure, transaction-monitoring systems, and compliance teams requires significant upfront and ongoing investment
Customer frictionLengthy onboarding and verification processes can deter legitimate users, particularly in developing markets with limited documentation
Data breach exposureCollecting and storing extensive personal identification data creates a high-value target for cybercriminals
Jurisdictional complexityTravel Rule thresholds, KYC standards, and EDD triggers differ by country, complicating compliance for globally active exchanges
Rapidly evolving obligationsNew guidance – especially around DeFi, NFTs, and stablecoins – means requirements can change faster than firms can update their programmes
Beneficial ownership gapsIdentifying ultimate beneficial owners of complex corporate structures remains a persistent practical challenge

Risk Management Tips:

  1. Adopt a risk-based approach – concentrate enhanced resources on the highest-risk customer segments and transaction types rather than applying maximum scrutiny to everyone.
  2. Automate KYC and transaction monitoring where possible; manual-only processes are slow and error-prone, particularly for high-volume crypto exchanges.
  3. Maintain a live sanctions-list integration that updates in real time; stale lists create liability when newly sanctioned entities slip through.
  4. For the Travel Rule, select a compliant messaging protocol (e.g., TRISA, OpenVASP, or a travel-rule software vendor) and test data-sharing with counterparty VASPs before going live.
  5. Document every compliance decision – including the rationale for not filing a SAR – to demonstrate good faith during regulatory examinations.

 FAQ

What is the minimum AML programme a crypto exchange must have?

At minimum a crypto exchange registered as a Money Services Business in the US must have: a written AML policy; a designated compliance officer; ongoing training for employees; independent testing; and a customer identification programme. FATF requires equivalent controls globally, adding CDD, EDD, transaction monitoring, SAR filing, record-keeping, and Travel Rule compliance for VASPs.

What is the FATF Travel Rule threshold for crypto?

FATF recommends applying the Travel Rule to virtual-asset transfers of $1,000 / €1,000 or more. The US has set its threshold at $3,000, consistent with the existing wire-transfer rule. EU member states implementing the revised Transfer of Funds Regulation apply a €0 threshold (i.e., all transfers regardless of amount).

How long must AML records be kept?

Most jurisdictions require a minimum of five years from the end of the business relationship or the date of the transaction. Some jurisdictions (e.g., certain EU member states) mandate seven years. Records must be kept in a form that can be readily retrieved and provided to authorities.

What triggers Enhanced Due Diligence (EDD)?

EDD is triggered by elevated risk factors including: the customer is a Politically Exposed Person (PEP) or a close associate of one; the customer is based in a high-risk jurisdiction listed by FATF; the nature of the business relationship is unusually complex; transaction volumes are unusually high relative to the customer’s stated business; or the source of funds cannot be readily verified.

Are DeFi protocols subject to AML requirements?

FATF’s updated guidance (2021) states that DeFi protocols where developers, founders, or governance token holders exercise effective control may constitute VASPs and be subject to AML requirements. Protocols that are genuinely decentralised with no controlling party sit in a grey area, but regulators in the US, EU, and UK are actively developing clearer rules.

Sources

  • https://www.fatf-gafi.org/en/topics/virtual-assets.html
  • https://www.chainup.com/academy/kyc-aml-crypto-exchanges-compliance-guide/
  • https://notabene.id/crypto-travel-rule-101/aml-crypto
  • https://sumsub.com/blog/crypto-aml-guide/
  • https://financialcrimeacademy.org/cryptocurrency-aml-guidelines-2/

UEEx Tip: If you are building or operating a crypto business, map your specific product types (spot trading, derivatives, custody, staking) against the AML requirements of each jurisdiction you serve – obligations can differ significantly by product, and a one-size-fits-all compliance programme may leave gaps in higher-risk activities.

Disclaimer: This content is for educational purposes only and does not constitute financial advice.

UEEx – Defining the Language of Crypto

Check your own numbers

The Free UEEx Calculator returns liquidation price, margin usage and fees for any position size

UEEx Weekly Digest

Market analysis and security alerts, read by 10,000 traders