Cryptocurrency exchanges should use a tiered KYC model that matches data collection to transaction risk and regulatory thresholds. Start with basic identity checks, then require stronger verification as transaction volumes rise. Once identity is verified, run sanctions screening, PEP screening, and adverse media checks before allowing higher-risk activity. The key is to combine customer due diligence with ongoing risk-based review.
How KYC Tiers Should Reflect Customer Risk
KYC should be structured as a graduated control, not a single onboarding event. Low-value or low-risk customers can usually be handled with lighter identity collection and basic screening, while higher-volume, higher-risk, or cross-border activity justifies deeper verification and stronger evidence of who the customer is. The design goal is proportionality: collect enough information to understand the customer, the source of activity, and the risk profile that will shape later screening.
For cryptocurrency exchanges, tiering works best when the KYC decision is tied to measurable thresholds such as transaction limits, funding sources, jurisdictional exposure, and account behavior. That keeps the process defensible and reduces unnecessary friction for low-risk users while ensuring the exchange gathers stronger proof before allowing materially more exposure.
A practical model is to treat each tier as a change in assurance. At the first tier, the exchange is usually confirming basic identity attributes and screening against baseline lists. At the next tier, it should require stronger documentary verification, beneficial ownership or control checks where relevant, and a clearer understanding of expected activity. This is the point where a customer’s profile should be strong enough to support ongoing monitoring and escalation if behavior changes.
How Sanctions Screening Fits Into the Onboarding Flow
Sanctions screening should not wait until after a customer becomes active at scale. It belongs in the onboarding flow and must also be repeated as part of ongoing review, because a customer who passes initial checks can later become higher risk through updated sanctions lists, changed ownership, wallet reuse, or altered transaction patterns. Screening is therefore a gate and a monitoring control, not a one-time formality.
The exchange should screen the customer, beneficial owners where applicable, and any other relevant parties before allowing higher-risk activity. For higher tiers, the screening decision should be more conservative because the consequences of missing a match are greater and the customer’s transaction privileges are larger. That is especially important where the exchange supports cross-border transfers, third-party funding, or business accounts with multiple controllers.
Screening quality depends on more than the list itself. The exchange needs name-quality controls, transliteration handling, alias matching, and a documented approach to false positives. If the review process is too aggressive, it creates operational drag; if it is too loose, it can let prohibited activity through. The right balance is a risk-based review process with clear escalation rules for uncertain matches.
What a Risk-Based Operating Model Looks Like in Practice
The most effective model combines customer due diligence, sanctions screening, PEP screening, and adverse media review into a single risk tiering workflow. Low-risk retail users can be covered with lighter evidence and automated screening, but the exchange should reserve stronger verification and human review for customers whose activity, geography, ownership structure, or transaction size makes the exposure materially higher.
The strongest control point is not the initial upload of documents, it is the decision logic that decides when a customer moves from one tier to the next. That logic should be explicit, auditable, and aligned to the product features that increase risk, such as higher withdrawal limits, institutional access, OTC activity, or access to faster settlement paths. When the tier changes, the review standard should change with it.
Exchanges should also keep the KYC record and the screening record connected. A customer profile that shows high-risk geography, adverse media concerns, or PEP exposure should feed directly into the screening cadence and the approval threshold. Where the exchange offers business accounts, the model should extend to controllers, signers, and other persons who can materially influence account use.
Risk and Threat Considerations
Weak tiering creates two different problems: overcollection for ordinary users and undercontrol for higher-risk customers. The second is the more serious security and compliance issue, because sanctions exposure, false identity, hidden ownership, or account misuse can pass through onboarding and only surface after funds have moved.
Failure mechanism: If screening is treated as a one-time onboarding task, list updates, ownership changes, and behavior shifts can leave a previously acceptable customer outside current risk controls. If tier escalation is not linked to transaction limits and activity patterns, the exchange may never apply the stronger checks that the customer’s risk actually warrants.
Impact: The exchange can onboard customers whose sanctioned status, political exposure, or adverse media risk should have triggered review, and the resulting exposure can include regulatory action, asset freeze obligations, reputational harm, and difficulty tracing illicit flows after the fact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Cryptocurrency customers are external users whose identity must be verified before access. |
| AC-3 — Access Enforcement | Tiered KYC and sanctions decisions govern what account actions a customer may perform. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Ongoing review of screening matches and activity changes depends on auditability. | |
| Recommendation — Apply IA-8 to verify customer identities before enabling higher-risk exchange activity. Enforce access limits that change with KYC tier and screening status. Review screening and escalation events to detect changes in customer risk. | ||
| CIS Controls v8 | CIS-5 — Account Management | Customer tiering and review are account governance and lifecycle controls. |
| Recommendation — Separate account approval tiers and revalidate access when risk changes. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Tiered KYC and sanctions screening determine access to exchange services. |
| Recommendation — Set access conditions that reflect customer risk tier and screening outcome. | ||
| PCI DSS v4.0 | 3.2.1 — Not stored once authenticated | Any payment-card-adjacent onboarding data handling must avoid unnecessary retention of sensitive data. |
| Recommendation — Minimise retention of sensitive onboarding data to reduce exposure. | ||
Practitioner Guidance
What to verify: Make sure each tier has a written trigger for entry and escalation, such as limits, jurisdiction, legal form, source-of-funds complexity, or unusual activity. If a customer can move to a higher-risk product without a corresponding increase in verification, the model is incomplete.
Decision rule: If the exchange is granting materially higher transaction capability, require stronger identity proofing and a tighter screening standard before approval. If the customer remains low-risk and low-volume, keep the process lighter but still searchable, repeatable, and reviewable.
Common mistake: Treating sanctions screening as separate from KYC. In practice, the useful control is a single risk-based workflow where identity confidence, list screening, and ongoing monitoring inform each other.
Practitioner takeaway: The right structure is not “light KYC for everyone” or “full KYC for everyone”, it is a tiered model where stronger verification and more conservative screening arrive exactly when the customer’s risk, access, or transaction authority increases.
Related resources from NHI Mgmt Group
- How should fintech teams structure KYC and AML controls across the customer lifecycle?
- Why does sanctions and PEP screening reduce regulatory and financial risk in KYC and AML programmes?
- How should regulated businesses structure an AML programme to detect money laundering across different customer and transaction channels?
- Why do nested cryptocurrency services create sanctions and money-laundering risk for exchanges that host them?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org