Join our Newsletter — 33% off our NHI Course

Why do banks face regulatory risk even when they do not offer cryptocurrency custody themselves?

A bank can still be exposed when its customers use bank accounts to fund crypto purchases that later support sanctioned activity, darknet transactions, or ransomware cash-outs. Regulators care about the institution’s visibility into customer behavior and whether it can identify, assess, and escalate higher-risk activity. Ignoring that flow can create a gap between business strategy and compliance obligations.

Why the regulatory exposure exists even without custody

The risk is not limited to holding crypto assets or private keys. Banks can still create a permissive financial pathway when fiat accounts, cards, or payment rails are used to fund activity that later links to sanctions exposure, darknet commerce, or ransomware monetization. Supervisors look at whether the bank can see, understand, and act on those flows, not only whether it directly stores crypto.

That means the institution’s obligation is driven by customer behaviour, transaction context, and escalation discipline. If the bank cannot connect account activity to higher-risk outcomes, the gap itself becomes a compliance issue, even when the bank is not the custodian of the digital asset.

What regulators are actually judging

Regulatory concern usually centers on whether the bank has an adequate monitoring and governance response to known-risk typologies. A bank that allows customer accounts to repeatedly fund crypto purchases tied to illicit activity may be seen as missing suspicious activity patterns, even if the bank never touches the destination wallet or exchange account.

This is why the key question is not “Do we offer custody?” but “Do we have visibility into how our accounts are being used, and can we escalate unusual or high-risk behaviour in a defensible way?” The relevant control failure is often a weak bridge between transaction monitoring, customer risk scoring, and case handling.

In practice, the exposure can extend into sanctions screening, AML investigation quality, and the consistency of decisions across business lines. Where the bank’s strategy allows obvious risk signals to pass without review, regulators may view the issue as governance failure rather than product design.

Why the same flow can become a control problem

Crypto-related payments create a traceable but often fragmented risk chain. A customer may move funds from a bank account to an exchange, convert into crypto, and then use that value in ways the bank never directly sees. Even so, the originating institution can still be expected to identify patterns that suggest layering, mule activity, fraud proceeds, or ransomware cash-out support.

This is where visibility, escalation thresholds, and customer due diligence matter. A bank does not need perfect end-to-end attribution to face risk; it needs a reasonable ability to detect when a customer flow is inconsistent with the account profile or with the bank’s own risk appetite. When that ability is weak, the institution can be exposed for failing to identify and challenge the activity it does observe.

For practitioners, the practical lesson is to treat “non-custodial” as an implementation fact, not a compliance shield. The bank’s obligations follow the payment path it enables, especially when the path can support illicit financing or cash-out behaviour.

Risk and Threat Considerations

Banks face exposure because criminals can use ordinary banking relationships to fund activity that is later converted, layered, or withdrawn through crypto rails. The risk is not just direct loss, but the possibility that the institution becomes part of the transaction chain supporting sanctioned actors, fraud, ransomware, or other high-risk activity.

Failure mechanism: Monitoring may be too narrow to connect customer deposits, transfers, and onward crypto-related behaviour into a coherent risk view, so suspicious patterns are not escalated or are escalated too late.

Impact: The bank can inherit regulatory scrutiny, remediation burden, and potential enforcement exposure because its controls did not keep pace with the actual use of its accounts.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while EU AI Act defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Banks must review transaction activity and escalate suspicious crypto-related flows.
AC-6 — Least Privilege Limits internal access to customer risk data and case handling in sensitive investigations.
SI-4 — System Monitoring Continuous monitoring is needed to detect higher-risk payment behavior tied to crypto activity.
Recommendation — Analyze alerts and account activity for suspicious funding patterns and escalate exceptions promptly. Restrict case and investigation access to staff who need it for AML and sanctions review. Monitor funding and transfer patterns for indicators of illicit crypto-related activity.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy The bank must align crypto-related payment risk with enterprise risk appetite and compliance obligations.
DE.CM-01 — Monitoring for Unauthorized Activities Observed account behavior can indicate suspicious or unauthorized crypto-funded activity.
Recommendation — Incorporate crypto-related payment pathways into the institution’s risk strategy and appetite. Continuously monitor customer transaction behavior for suspicious activity and escalation triggers.
CIS Controls v8 CIS-8 — Audit Log Management Audit evidence is needed to support investigations into risky account-to-crypto flows.
CIS-17 — Incident Response Management Crypto-linked suspicious activity often requires coordinated investigation and response.
Recommendation — Retain and review logs needed to reconstruct suspicious funding and escalation decisions. Route high-risk crypto-related cases into a documented incident and escalation process.
EU AI Act Regulatory Framework for AI AI governance is not materially central to this banking crypto-risk question, so no mapping is retained.

Practitioner Guidance

What to prioritise: Focus first on the transaction pathways your institution actually enables, especially fiat on-ramps, rapid movement into high-risk counterparties, and repeated flows that do not fit the stated customer profile. Those are the points where monitoring and escalation are most likely to fail.

What to verify: Confirm that customer risk ratings, alert logic, and case management are linked closely enough to distinguish ordinary crypto-adjacent usage from activity that merits investigation. If the bank cannot explain why a high-risk flow was cleared, it likely cannot defend the control.

Practitioner takeaway: The issue is not whether the bank stores crypto, but whether it can demonstrate credible oversight of the money movement that enables crypto-related harm.