Join our Newsletter — 33% off our NHI Course

How should virtual currency businesses prepare for bank onboarding and enhanced due diligence?

Virtual currency businesses should prepare a clear, credible package that explains ownership, leadership, licensing, compliance philosophy, transaction patterns, and the controls supporting their activity. Banks will also look for evidence that AML policies, transaction monitoring, and governance are real and current. The strongest approach is proactive transparency, because gaps in explanation often trigger deeper review and slower account approval.

What banks want to see before they open the account

Bank onboarding is not won by a generic compliance statement. It is won by a narrative that lets the bank understand who controls the business, what the business does, where the funds come from, and how customer and transaction risk is managed in practice. That package should be internally consistent, easy to verify, and current enough to support enhanced due diligence.

A strong onboarding pack usually includes the ownership structure, leadership bios, licences or registrations, core products and services, target jurisdictions, expected counterparties, and a plain-English explanation of the business model. Banks often treat clarity as a control signal: when the story is coherent, the review is usually faster; when it is fragmented, the case often moves into deeper scrutiny.

For virtual currency businesses, the bank will also want to understand how the firm handles customer onboarding, sanctions screening, suspicious activity escalation, and transaction monitoring. The more clearly those controls are documented and evidenced, the easier it is for the bank to map the business to its own AML obligations and internal risk appetite. A useful baseline is the FATF Recommendations, AML and KYC framework, which underpins much of the global due diligence expectation for virtual asset activity.

How to translate your AML and governance controls into bank language

Banks do not only ask whether a policy exists. They look for evidence that the policy is operational, owned, and reviewed. That means showing who is responsible for AML decisions, how alerts are handled, how exceptions are approved, and how governance changes are escalated. If the bank cannot see a living control environment, it will assume the risk is still being built.

The most effective explanation is often a short control map that ties business activity to monitoring and escalation. For example, explain how deposits and withdrawals are reviewed, what triggers enhanced checks, how alerts are triaged, and what records are retained. If you serve higher-risk geographies, privacy-preserving services, large-value flows, or rapid movement patterns, say so directly and describe the compensating controls rather than letting the bank infer them from transaction data.

This is also where ownership matters. Banks want to know whether compliance, operations, legal, and senior management are aligned, and whether someone can answer questions without improvisation. Internal governance should be visible enough to support escalation, because weak ownership is often interpreted as weak control. A practical way to strengthen that story is to align your account-opening material with the control lifecycle described in the IAM and IGA Basics and the Joiner-Mover-Leaver (JML) Guide, because banks often probe whether access, approvals, and offboarding are actually governed or merely documented.

Which evidence reduces friction in enhanced due diligence

Enhanced due diligence becomes easier when the bank can verify facts quickly. The most useful evidence is usually recent, specific, and cross-referenced: corporate formation documents, licence status, AML policy extracts, risk assessments, monitoring workflow summaries, sample reports, and proof that governance meetings or reviews are happening on schedule. If the business uses vendors for screening, custody, or blockchain analytics, the bank may also ask how third-party reliance is controlled.

Transaction behaviour should be described in a way that matches real operations. Give expected volumes, average ticket sizes, corridor exposure, customer segments, and any seasonal or product-driven spikes. If actual activity differs from the original plan, explain why. The bank is not looking for perfection, it is looking for consistency and a credible explanation for variance. A well-organised evidence pack often helps because it reduces the number of follow-up questions, especially when paired with clear due diligence around customer identity and source-of-funds practices, as reflected in the Identity Proofing and KYC Guide.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 — Organizational Context Bank onboarding depends on clear business purpose and governance context.
Recommendation — Document ownership, services, and risk posture so reviewers can assess the business consistently.
CIS Controls v8 CIS-5 — Account Management Onboarding and due diligence hinge on accountable access and lifecycle controls.
Recommendation — Show how access, approvals, and offboarding are governed and reviewed.
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Banks expect monitoring and escalation evidence for suspicious or unusual activity.
IA-5 — Authenticator Management Due diligence often includes how credentials and access are controlled across operations.
Recommendation — Demonstrate how alerts are reviewed, escalated, and retained for oversight. Provide evidence that credentials and access are issued, rotated, and revoked under process.

Practitioner Guidance

What to prioritise: Build the onboarding pack as if a compliance analyst will test every claim against live evidence. The highest-value items are the ones that let the bank connect your legal structure, control environment, and transaction profile without relying on verbal reassurance.

What to verify: Before submitting, verify that ownership charts, licence references, policy dates, transaction descriptions, and control owners all match each other. Small inconsistencies are a common reason for delayed approval because they create questions about record quality and governance discipline.

Common mistake: Many virtual currency businesses over-explain the technology and under-explain the control environment. Banks usually care less about the product pitch than about whether you can evidence AML oversight, escalation, and ongoing monitoring.

Practitioner takeaway: The best preparation is not a polished sales deck, it is a defensible control narrative backed by current evidence. If the bank can understand your business, verify your governance, and predict how you manage risk, onboarding friction usually drops.