KYC and AML in crypto, explained
AML is the framework for stopping illicit finance; KYC is one tool within it. Here is how both apply to regulated crypto businesses, including the Travel Rule.
Quick answer
Anti-money laundering (AML) is the framework that stops the financial system being used for illicit finance; Know Your Customer (KYC) is the customer-verification part of it. These rules reached crypto when standards were extended to virtual-asset service providers, driven by FATF. Regulated businesses verify identity, monitor transactions, screen sanctions, report suspicious activity, and, under the Travel Rule, share sender and recipient information.
Key points
- AML is the overall framework; KYC is the customer-verification component within it.
- Obligations attach to regulated intermediaries (VASPs), not to protocols or peer-to-peer users.
- AML programmes include monitoring, sanctions screening, reporting, and record-keeping.
- The FATF Travel Rule makes VASPs share originator and beneficiary information on transfers.
- Public blockchains are pseudonymous, not anonymous, and analytics can link addresses to identities.
Two related but distinct ideas
Anti-money laundering (AML) is the broad legal and regulatory framework designed to stop the financial system from being used to launder criminal proceeds or finance terrorism. Know Your Customer (KYC) is one component of AML: the set of processes a regulated business uses to verify who its customers are. In everyday speech the two are often merged, but it helps to keep them separate. AML is the goal and the obligation; KYC is one of the tools used to meet it. A regulated crypto exchange asking for your identity documents is performing KYC as part of a wider AML programme that also includes monitoring, screening, and reporting.
Why these rules reached crypto
AML rules long predate crypto and apply across banking and finance. They reached crypto because the same standards that govern other financial intermediaries were extended to cover virtual-asset service providers (VASPs), a category that includes exchanges, certain custodians, and similar businesses. The global standard-setter here is the Financial Action Task Force (FATF), an intergovernmental body whose recommendations most countries implement. When FATF extended its standards to cover virtual assets and the businesses that handle them, national regulators followed, which is why KYC and AML obligations on crypto businesses now look broadly similar across very different jurisdictions.
It is worth being precise about scope. These obligations attach to regulated intermediaries, not to the underlying protocols or to individuals transacting peer to peer. The blockchain itself does not perform KYC; the regulated business sitting between you and it does.
What KYC actually involves
KYC, sometimes framed within the broader concept of customer due diligence (CDD), typically has several layers:
- Identification and verification. Collecting identifying information, such as name, date of birth, and address, and verifying it against reliable documents or data, often government-issued identification.
- Risk assessment. Assessing the risk a customer presents, which can depend on factors like their profile, activity, and geography.
- Enhanced due diligence. Applying additional scrutiny to higher-risk customers, for example politically exposed persons or those in higher-risk jurisdictions.
- Ongoing monitoring. KYC is not a one-time gate at signup; regulated businesses are expected to keep monitoring activity for consistency with what they know about the customer.
The purpose is to prevent anonymous accounts from being used to move illicit funds and to give investigators a starting point if wrongdoing is suspected.
The core of AML monitoring
Beyond onboarding, an AML programme at a regulated crypto business generally includes several ongoing functions:
- Transaction monitoring to detect patterns that may indicate money laundering, such as structuring or unusual flows.
- Sanctions screening against government-maintained sanctions lists, so the business does not transact with prohibited persons or entities.
- Suspicious activity reporting, under which the business must report suspicious transactions to the relevant national financial-intelligence unit, often without tipping off the customer.
- Record-keeping, retaining customer and transaction records for a defined period so that they are available to authorities.
Crypto adds a distinctive tool to this mix: blockchain analytics. Because most blockchains are public and permanent ledgers, specialised firms and compliance teams can trace the flow of funds between addresses and flag connections to known illicit sources. This is a double-edged feature. The transparency that lets anyone audit a chain is the same transparency that makes sophisticated on-chain surveillance possible.
The FATF Travel Rule
One AML requirement is specific enough to name directly. The Travel Rule, drawn from FATF Recommendation 16 and originally designed for traditional wire transfers, was extended to virtual-asset transfers. In principle it requires that when a transfer moves between VASPs, certain information about the originator (the sender) and the beneficiary (the recipient) must travel with the transaction, collected, verified where required, and shared between the sending and receiving businesses.
The practical effect is that regulated crypto businesses exchange identifying information about the parties to qualifying transfers, off-chain, alongside the on-chain movement of value. Implementation details, including any thresholds and exactly what data must be shared, are set by each jurisdiction when it transposes the standard, so they differ from country to country. Extending a rule built for the banking system to a technology where a destination may be a self-hosted wallet rather than another regulated business has been one of the harder compliance challenges in the sector.
What this means for users
For someone using regulated services, the principles translate into a few practical expectations:
- Expect identity verification at reputable, regulated platforms; the absence of any KYC at a service handling significant value can itself be a warning sign about its regulatory standing.
- Expect that your activity on such platforms is monitored, screened against sanctions lists, and recorded, and that suspicious activity may be reported to authorities.
- Expect that transfers between regulated businesses may carry identifying information under Travel Rule implementations.
- Understand that public blockchains are not anonymous; they are pseudonymous, and analytics can often link addresses to identities, especially where those addresses have touched a KYC’d service.
The self-hosted wallet challenge
A recurring difficulty is what happens when value moves between a regulated business and a self-hosted wallet, one controlled directly by an individual rather than by another regulated intermediary. The AML framework was built around transfers between institutions, each of which can identify its own customer. When one end of a transfer is a self-hosted wallet, there is no counterpart institution to exchange information with, and the regulated business may instead be expected to gather or verify information about the wallet’s owner in other ways. Jurisdictions have taken different positions on how much scrutiny such transfers require, and this remains one of the least settled areas of crypto AML precisely because it sits at the boundary between the regulated and the self-custodied worlds.
Data retention and its own risk
The flip side of collecting identity data is that it must be stored, and stored data is a target. When a regulated business gathers identification documents, addresses, and transaction histories to satisfy KYC and record-keeping obligations, it creates a concentrated store of sensitive personal information. If that store is breached, the very data collected for compliance can be exposed. This does not make the obligations wrong, but it is an honest part of the picture: mandatory data collection shifts risk as well as reducing it, and how well an intermediary protects what it gathers is a legitimate factor in judging it.
The privacy tension
KYC and AML sit in genuine tension with the privacy values that motivated much of crypto’s early development. That tension is real and worth stating plainly rather than glossing over. Regulators argue these controls are necessary to keep the financial system from being abused and to protect consumers; privacy advocates argue they recreate the surveillance and gatekeeping that decentralized systems were meant to reduce, and that mass collection of identity data itself creates risk, since breached KYC databases expose exactly the sensitive information they gathered. Both observations can be true at once. Understanding KYC and AML is not about resolving that debate; it is about seeing clearly what regulated intermediaries are required to do, why, and where the boundaries of those obligations lie.
Sources
Frequently asked questions
What is the difference between KYC and AML?
Do these rules apply to peer-to-peer transactions?
What is the FATF Travel Rule?
Is crypto anonymous?
Why do exchanges ask for my identity documents?
Does more KYC make crypto safer?
Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.