Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do virtual asset platforms need both KYC…
Identity Beyond IAM

Why do virtual asset platforms need both KYC and AML screening rather than one control alone?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Identity Beyond IAM

KYC establishes who the customer is, while AML screening helps detect sanctions exposure, suspicious counterparties, and other financial crime indicators. Using only one control leaves gaps in risk coverage. For crypto platforms, the combination matters because user onboarding, transaction activity, and regulatory expectations all create different trust decisions that must be validated separately.

Why This Matters for Security Teams

For virtual asset platforms, KYC and aml screening answer different trust questions. KYC establishes who is opening the account, while AML screening looks for sanctions exposure, suspicious counterparties, and transaction patterns that can indicate financial crime. Treating either control as sufficient creates a false sense of coverage, especially when onboarding risk and activity risk are evaluated at different points in the customer lifecycle. FATF’s AML and KYC framework makes this separation explicit.

The operational issue is that bad actors rarely fail both checks in the same way. A synthetic or stolen identity may pass onboarding but still send funds to high-risk wallets later, while a legitimate customer may become risky because of counterparties, geography, or behavioural changes after account creation. That is why platforms need both identity verification and ongoing monitoring, not a single gate at signup. NHI Mgmt Group’s Ultimate Guide to NHIs shows how often one control layer fails to reveal the full exposure picture, and the same pattern appears in financial crime workflows.

In practice, many security teams encounter the gap only after onboarding has already approved the account and suspicious activity has already moved through the platform.

How It Works in Practice

Effective virtual asset governance uses kyc and aml as complementary controls, not duplicates. KYC verifies customer identity at onboarding through document checks, proof of address, beneficial ownership, or stronger identity proofing where required. AML screening then evaluates sanctions lists, adverse media, politically exposed persons, wallet risk, and transaction behaviour over time. The distinction matters because one control is largely static, while the other is continuous and event-driven. FATF guidance remains the primary global reference for this separation, and eIDAS 2.0 shows how stronger digital identity assurance is increasingly part of the broader trust stack.

A practical implementation usually includes:

  • Identity proofing before account activation, with tiered assurance based on product risk.
  • Sanctions and watchlist screening at onboarding and again on a recurring basis.
  • Transaction monitoring for layering, structuring, rapid movement, and exposure to high-risk counterparties.
  • Case management and escalation paths when screening results conflict or degrade over time.
  • Audit trails that preserve why the customer was approved, blocked, or re-reviewed.

This layered model aligns with the same governance logic NHI Mgmt Group documents in the Ultimate Guide to NHIs — Standards: separate the identity claim from the ongoing trust decision, then re-evaluate when context changes. The point is not just to know who the customer is, but whether the platform should continue transacting with that customer under current risk conditions. These controls tend to break down when screening data is fragmented across onboarding, compliance, and transaction-monitoring systems because no single team can see the full risk signal.

Common Variations and Edge Cases

Tighter screening often increases onboarding friction and compliance overhead, so organisations have to balance customer conversion against abuse prevention. That tradeoff is real, especially for high-volume platforms, cross-border services, and products with low-value transactions where manual review can quickly overwhelm operations. Current guidance suggests risk-based segmentation is better than applying the same depth of KYC and AML to every user.

There is no universal standard for this yet, but several edge cases are consistent. Lower-risk users may need lighter KYC at signup with stronger transaction monitoring later, while higher-risk products may justify enhanced due diligence, source-of-funds checks, or ongoing wallet intelligence. Shared accounts, corporate customers, intermediaries, and self-custody wallets also complicate screening because the beneficial owner, transacting party, and end beneficiary may not be the same person. NHI Mgmt Group’s research on the Ultimate Guide to NHIs — The NHI Market reinforces a useful lesson: trust decisions need to be lifecycle-aware, not one-time only.

Platforms that rely on one control alone usually fail when customer behaviour changes after onboarding, when counterparties become the risk signal, or when regulatory obligations require separate evidence for identity, sanctions, and transaction monitoring.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST AI RMF and NIST SP 800-63 set the technical controls, while NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Access control needs identity proofing plus ongoing authorization decisions.
NIST AI RMFGOVERNGovernance requires clear accountability for identity and financial crime controls.
NIST SP 800-63IALIdentity assurance level supports KYC strength and proofing decisions.
NIS2Risk management and incident handling expectations mirror layered screening logic.

Separate customer identity verification from transaction risk monitoring and review both continuously.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org