Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should cryptocurrency exchanges structure KYC and sanctions…
Governance, Ownership & Risk

How should cryptocurrency exchanges structure KYC and sanctions screening across different customer risk tiers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

Cryptocurrency exchanges should use a tiered KYC model that matches data collection to transaction risk and regulatory thresholds. Start with basic identity checks, then require stronger verification as transaction volumes rise. Once identity is verified, run sanctions screening, PEP screening, and adverse media checks before allowing higher-risk activity. The key is to combine customer due diligence with ongoing risk-based review.

How KYC Tiers Should Reflect Customer Risk

KYC should be structured as a graduated control, not a single onboarding event. Low-value or low-risk customers can usually be handled with lighter identity collection and basic screening, while higher-volume, higher-risk, or cross-border activity justifies deeper verification and stronger evidence of who the customer is. The design goal is proportionality: collect enough information to understand the customer, the source of activity, and the risk profile that will shape later screening.

For cryptocurrency exchanges, tiering works best when the KYC decision is tied to measurable thresholds such as transaction limits, funding sources, jurisdictional exposure, and account behavior. That keeps the process defensible and reduces unnecessary friction for low-risk users while ensuring the exchange gathers stronger proof before allowing materially more exposure.

A practical model is to treat each tier as a change in assurance. At the first tier, the exchange is usually confirming basic identity attributes and screening against baseline lists. At the next tier, it should require stronger documentary verification, beneficial ownership or control checks where relevant, and a clearer understanding of expected activity. This is the point where a customer’s profile should be strong enough to support ongoing monitoring and escalation if behavior changes.

How Sanctions Screening Fits Into the Onboarding Flow

Sanctions screening should not wait until after a customer becomes active at scale. It belongs in the onboarding flow and must also be repeated as part of ongoing review, because a customer who passes initial checks can later become higher risk through updated sanctions lists, changed ownership, wallet reuse, or altered transaction patterns. Screening is therefore a gate and a monitoring control, not a one-time formality.

The exchange should screen the customer, beneficial owners where applicable, and any other relevant parties before allowing higher-risk activity. For higher tiers, the screening decision should be more conservative because the consequences of missing a match are greater and the customer’s transaction privileges are larger. That is especially important where the exchange supports cross-border transfers, third-party funding, or business accounts with multiple controllers.

Screening quality depends on more than the list itself. The exchange needs name-quality controls, transliteration handling, alias matching, and a documented approach to false positives. If the review process is too aggressive, it creates operational drag; if it is too loose, it can let prohibited activity through. The right balance is a risk-based review process with clear escalation rules for uncertain matches.

What a Risk-Based Operating Model Looks Like in Practice

The most effective model combines customer due diligence, sanctions screening, PEP screening, and adverse media review into a single risk tiering workflow. Low-risk retail users can be covered with lighter evidence and automated screening, but the exchange should reserve stronger verification and human review for customers whose activity, geography, ownership structure, or transaction size makes the exposure materially higher.

The strongest control point is not the initial upload of documents, it is the decision logic that decides when a customer moves from one tier to the next. That logic should be explicit, auditable, and aligned to the product features that increase risk, such as higher withdrawal limits, institutional access, OTC activity, or access to faster settlement paths. When the tier changes, the review standard should change with it.

Exchanges should also keep the KYC record and the screening record connected. A customer profile that shows high-risk geography, adverse media concerns, or PEP exposure should feed directly into the screening cadence and the approval threshold. Where the exchange offers business accounts, the model should extend to controllers, signers, and other persons who can materially influence account use.

Risk and Threat Considerations

Weak tiering creates two different problems: overcollection for ordinary users and undercontrol for higher-risk customers. The second is the more serious security and compliance issue, because sanctions exposure, false identity, hidden ownership, or account misuse can pass through onboarding and only surface after funds have moved.

Failure mechanism: If screening is treated as a one-time onboarding task, list updates, ownership changes, and behavior shifts can leave a previously acceptable customer outside current risk controls. If tier escalation is not linked to transaction limits and activity patterns, the exchange may never apply the stronger checks that the customer’s risk actually warrants.

Impact: The exchange can onboard customers whose sanctioned status, political exposure, or adverse media risk should have triggered review, and the resulting exposure can include regulatory action, asset freeze obligations, reputational harm, and difficulty tracing illicit flows after the fact.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Cryptocurrency customers are external users whose identity must be verified before access.
AC-3 — Access EnforcementTiered KYC and sanctions decisions govern what account actions a customer may perform.
AU-6 — Audit Record Review, Analysis, and ReportingOngoing review of screening matches and activity changes depends on auditability.
Recommendation — Apply IA-8 to verify customer identities before enabling higher-risk exchange activity. Enforce access limits that change with KYC tier and screening status. Review screening and escalation events to detect changes in customer risk.
CIS Controls v8CIS-5 — Account ManagementCustomer tiering and review are account governance and lifecycle controls.
Recommendation — Separate account approval tiers and revalidate access when risk changes.
ISO/IEC 27001:2022A.5.15 — Access controlTiered KYC and sanctions screening determine access to exchange services.
Recommendation — Set access conditions that reflect customer risk tier and screening outcome.
PCI DSS v4.03.2.1 — Not stored once authenticatedAny payment-card-adjacent onboarding data handling must avoid unnecessary retention of sensitive data.
Recommendation — Minimise retention of sensitive onboarding data to reduce exposure.

Practitioner Guidance

What to verify: Make sure each tier has a written trigger for entry and escalation, such as limits, jurisdiction, legal form, source-of-funds complexity, or unusual activity. If a customer can move to a higher-risk product without a corresponding increase in verification, the model is incomplete.

Decision rule: If the exchange is granting materially higher transaction capability, require stronger identity proofing and a tighter screening standard before approval. If the customer remains low-risk and low-volume, keep the process lighter but still searchable, repeatable, and reviewable.

Common mistake: Treating sanctions screening as separate from KYC. In practice, the useful control is a single risk-based workflow where identity confidence, list screening, and ongoing monitoring inform each other.

Practitioner takeaway: The right structure is not “light KYC for everyone” or “full KYC for everyone”, it is a tiered model where stronger verification and more conservative screening arrive exactly when the customer’s risk, access, or transaction authority increases.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org