Crypto exchanges should treat AML and KYC as a continuing control framework, not a one-time onboarding check. That means verifying customer identity, applying risk-based customer due diligence, screening for sanctions and suspicious activity, keeping complete transaction records, and filing reports with FIU-IND when required. Strong governance, staff training, and documented escalation paths are essential to make the programme defensible.
How AML and KYC should be structured for exchange operations
For a crypto exchange, AML and KYC work best as a layered operating model rather than a single onboarding gate. The core design should separate identity proofing, customer risk scoring, transaction monitoring, sanctions screening, recordkeeping, and reporting so each control can be tested and evidenced independently. That structure makes the programme easier to defend during audits and investigations.
The first practical choice is to tie controls to customer and activity risk, not to a static checklist. Low-risk retail accounts, higher-value traders, corporate accounts, and wallets with unusual transaction patterns should not be treated the same way. Risk-based handling is what keeps KYC from becoming perfunctory while allowing stronger due diligence where the exposure is actually higher.
Complete transaction records matter as much as identity records because AML review is usually pattern-driven, not point-in-time. Exchanges should be able to reconstruct who transacted, when, through which accounts or wallets, and what alerts or escalations followed. That means the control set must preserve evidence, not just approve users. FATF’s AML and KYC framework remains the clearest external baseline for this structure, especially around customer due diligence and suspicious activity reporting, and the full standard is available at FATF Recommendations, the AML and KYC framework.
India-specific compliance also benefits from strong governance around ownership and escalation. Someone must own the customer acceptance standard, someone must own monitoring thresholds, and someone must own the decision to file, freeze, restrict, or offboard when activity becomes suspicious. Without that separation, controls tend to exist on paper but fail in execution because exceptions are handled informally or too late.
Controls that make the programme defensible in practice
Defensibility comes from controls that are repeatable, documented, and reviewable. For KYC, that means identity verification at onboarding, periodic refresh for existing customers, and clear triggers for enhanced due diligence when behaviour changes. For AML, it means sanctions screening, transaction monitoring rules, alert investigation, and escalation to the reporting function when the case threshold is met. Each control should leave a traceable evidence trail.
Crypto exchanges should also treat wallet exposure and account behaviour as part of the control perimeter. A user may be “known” at onboarding and still become high risk if activity shows layering, rapid churn, structuring, or links to higher-risk counterparties. The monitoring programme therefore needs thresholds that are tuned to exchange behaviour, not copied blindly from traditional banking. Where the exchange uses cloud-hosted platforms or dependent service providers, security and compliance expectations should also be reflected in the broader control baseline, including ISO/IEC 27001:2022 Information Security Management and CIS Controls v8 for governance, access control, and logging discipline.
Record retention is not just a back-office issue. If investigators or regulators ask why a customer passed review, the exchange should be able to show the decision basis, the supporting documents, the rule or reviewer decision, and any subsequent case handling. That is what turns a compliance process into an auditable control system rather than a loose collection of forms.
For exchanges that integrate with banks, payment processors, custody providers, or other vendors, third-party assurance also matters. The relevant question is whether counterparties can preserve the same screening, alerting, and reporting standards across shared workflows. In practice, many exchange programmes map well to SOC 2 Trust Services Criteria for security, confidentiality, and processing integrity, because those criteria align with the need for evidence, control ownership, and repeatable operation.
Practitioner priorities for staying aligned with current rules
What to verify: Verify that your KYC files, monitoring rules, sanctions checks, case notes, and FIU-IND reporting workflow all align to the same customer identity and transaction record. Mismatched records are a common reason investigations stall even when the underlying control exists.
What to measure: Track alert-to-decision time, percentage of high-risk customers under enhanced due diligence, completeness of mandatory fields, and the share of alerts closed with documented rationale. Those measures show whether the programme is operational or merely nominal.
Common mistake: Treating onboarding as the finish line is the most common failure. For exchanges, the real risk usually emerges after account creation, when transaction patterns, source-of-funds concerns, and counterparty exposure become visible.
Practitioner takeaway: The strongest AML and KYC programmes are built around ongoing decision quality, not just identity collection, so the exchange can explain every high-risk outcome, every escalation, and every report with evidence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | AML monitoring depends on alert review and documented reporting of suspicious activity. |
| IA-2 — Identification and Authentication (Organizational Users) | Customer verification and access assurance rely on identity proofing and authentication controls. | |
| AC-6 — Least Privilege | Exchange staff and vendor access should be limited to the minimum needed for AML/KYC operations. | |
| Recommendation — Document alert review outcomes and retain investigation evidence for audit and regulatory review. Require strong identity verification before allowing account activation and risky actions. Restrict operational access so only approved staff can approve, override, or escalate cases. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | KYC and AML workflows require governed access to sensitive customer and case data. |
| A.8.15 — Logging | Defensible AML programmes need logs for monitoring, investigation, and evidence retention. | |
| Recommendation — Apply access rules to protect customer records, investigations, and reporting data. Log customer actions, alerts, investigations, and reporting steps with tamper-resistant retention. | ||
| SOC 2 (AICPA) | Security — Security | Exchange KYC and AML controls support secure, auditable handling of customer and transaction data. |
| Recommendation — Operate KYC and AML controls with documented ownership, review, and evidence retention. | ||
Related resources from NHI Mgmt Group
- How should fintech teams structure KYC and AML controls across the customer lifecycle?
- Why do KYC and AML controls need to stay distinct?
- Why do KYC, KYB, AML screening, and Travel Rule controls need to work together in crypto payments?
- How should crypto platforms balance faster onboarding with AML and KYC controls in regulated markets?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org