Join our Newsletter — 33% off our NHI Course

Crypto AML

Crypto AML is the set of controls, policies, and reporting obligations designed to prevent money laundering and related financial crime in cryptocurrency activity. It typically combines identity verification, transaction monitoring, suspicious activity reporting, and customer risk scoring so exchanges and wallet providers can detect abuse while meeting regulatory expectations.

Expanded Definition

Crypto AML covers the policies, controls, and oversight used to detect, prevent, and report money laundering risks in cryptocurrency activity. In practice, it sits at the intersection of transaction monitoring, customer due diligence, sanctions screening, and recordkeeping, with organisations applying risk-based controls to exchanges, brokers, wallet providers, and other virtual asset service providers. The term is broader than basic KYC because it includes ongoing monitoring after onboarding, not just identity collection at account creation.

Definitions vary across jurisdictions because crypto AML obligations are shaped by local licensing rules, travel rule implementation, and the way regulators classify virtual asset activity. Global guidance from the FATF Recommendations — AML and KYC Framework is often used as the baseline, but organisations still need to map that guidance to national reporting thresholds and supervision expectations. The concept is also distinct from broader crypto compliance because not every compliance issue is AML related; custody, consumer protection, and market integrity controls may apply separately.

The most common misapplication is treating wallet address collection as sufficient AML due diligence, which occurs when teams confuse blockchain visibility with verified customer identity and ongoing risk assessment.

Examples and Use Cases

Implementing crypto AML rigorously often introduces friction at onboarding and during high-risk transfers, requiring organisations to weigh faster account creation against stronger monitoring and investigative depth.

  • An exchange verifies a new customer, screens the source of funds, and assigns a risk score before allowing higher-value deposits.
  • A wallet provider flags rapid movement through multiple addresses and escalates the case for review when transaction patterns match layering behaviour.
  • A compliance team files a suspicious activity report after detecting coordinated deposits from accounts linked to fraud typologies.
  • A virtual asset platform applies enhanced due diligence to customers in higher-risk geographies or to entities with opaque beneficial ownership.
  • A firm aligns its internal program to FATF Recommendations — AML and KYC Framework while adapting alerts to the specific transaction patterns seen on-chain.

Use cases differ depending on the product model. Custodial services usually need stronger identity assurance and stronger monitoring of withdrawal behaviour, while non-custodial services may focus more heavily on exposure screening, traceability, and escalation workflows where regulation requires them.

Why It Matters for Security Teams

Crypto AML is not only a financial crime requirement; it is also an operational control that reduces exposure to fraud, sanctions breaches, account abuse, and regulatory enforcement. For security teams, weak AML processes can create blind spots where compromised accounts, mule activity, and stolen assets move through the platform before detection. The issue is especially important where identity assurance and Non-Human Identity governance intersect with automated trading, API access, and service accounts that can generate or move transactions at speed.

Security and compliance teams need shared visibility because attackers often exploit the gaps between onboarding, monitoring, and incident response. A control that works on paper may fail if alert thresholds are poorly tuned, if case management is disconnected from identity data, or if investigators cannot trace activity back to a verified customer or an internal privileged account. The most effective programs treat AML as a continuous detection discipline rather than a one-time verification step.

Organisations typically encounter the real cost of crypto AML weakness only after suspicious flows are traced to a breach, fraud ring, or regulatory inquiry, at which point remediation becomes operationally unavoidable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, and DORA define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-01 Crypto AML depends on verifying identities and access context before financial activity is allowed.
NIST SP 800-63 IAL2 Identity proofing quality affects how reliably a crypto AML program binds activity to a real customer.
NIST AI RMF Risk management principles align with monitoring models and human oversight used in crypto AML.
OWASP Non-Human Identity Top 10 API keys and service accounts can move crypto value and should be governed as NHIs.
DORA Operational resilience expectations apply when AML tooling or case workflows are disrupted.

Inventory non-human identities used in trading and transfer workflows and rotate their secrets tightly.