AML & Compliance in Crypto: What Businesses Need to Know
A few years ago, while I was still running a crypto hedge fund, I got a call from an operations manager at another company in the space. His business had accepted a Bitcoin payment from what looked like a perfectly legitimate client, and within two weeks their bank had frozen the account. The funds weren't "dirty" from the client's perspective - he simply hadn't checked, and hadn't been asked to check, where the coins had originated before reaching him. That moment is exactly when most businesses discover that compliance in digital assets isn't a legal afterthought. It's a condition for staying operational.
As more businesses - not just exchanges, but fintechs, payment companies, wealth managers, and even traditional companies now accepting crypto payments - move into this space, the question is no longer "do we need a compliance program," it's "would our program actually hold up under scrutiny." After years building and operating regulated financial products in crypto, and more recently focusing on blockchain investigations and digital asset tracing, I keep seeing the same mistakes repeat themselves - and the same handful of businesses survive precisely because they built serious compliance infrastructure early.
Why On-Chain Risk Doesn't Stay On-Chain
One of the most persistent misconceptions in crypto is that digital money is somehow "clean" simply because it moved through a new technological rail. In reality, every public blockchain is essentially an open ledger, and the full history of any given coin is visible to anyone who knows how to read it. That means every wallet address carries a history, and if a business receives funds that ever passed through an address tied to a hack, a scam, ransomware, or money laundering, that risk transfers to them automatically - regardless of intent or awareness.
Banks, regulators, and business partners learned this quickly. A bank that notices a client's account received funds routed through high-risk addresses doesn't usually ask questions first - it closes the account. That's why on-chain risk assessment has moved from "nice to have" to a core component of any serious compliance program: it's the only way to know, in real time, whether the money coming in is carrying risk you're about to inherit.
What a Working Compliance Program Actually Looks Like
A solid AML program in crypto isn't fundamentally different from a traditional compliance program, but it has to account for the speed, global reach, and partial anonymity that characterize digital assets. In my experience, every credible program rests on a handful of core elements:
- Customer and business due diligence (KYC/KYB) - not just at onboarding, but as an ongoing process that updates as a client's activity patterns change.
- Continuous transaction monitoring - systems that flag unusual patterns, structured transactions, or rapid movement across many addresses designed to obscure the source of funds.
- Sanctions and watchlist screening - automated checks at both the client level and the wallet-address level for any counterparty being interacted with.
- Suspicious activity reporting - a clear, documented, consistent process for escalating unusual cases to the right authorities, with a full record of how each decision was reached.
What distinguishes a good program isn't the checklist itself, it's the risk-based approach behind it. Not every client, every transaction, or every market warrants the same depth of scrutiny. A business that genuinely understands its own risk profile - client types, transaction volumes, geographies, asset classes - can allocate compliance resources intelligently, rather than drowning in generic checks that miss the actual risks it faces.
Where Blockchain Forensics Fits Into Compliance
This is where I, as a blockchain investigator, tend to get pulled into a business's story - often well after "basic compliance" already exists on paper. Standard transaction monitoring flags anomalies, but it doesn't always explain what's actually behind a specific wallet address. That's where real forensic analysis comes in: wallet risk scoring based on an address's full activity history, and counterparty exposure analysis - mapping a wallet's indirect connections to problematic actors, even several hops deep in the transaction chain.
This capability matters in three main contexts: at onboarding (verifying the source of funds before approving an account), in real time (catching new exposure that emerges after a client is already active), and retrospectively (when a concern surfaces and you need to understand the full scope of risk for reporting purposes or a regulatory response). Businesses that build forensic analysis into their compliance program as a structural layer - not just as a firefighting tool - tend to avoid crises that would otherwise be far costlier, financially and reputationally.
The Mistakes I See Businesses Make Over and Over
Growing businesses tend to repeat the same mistakes, almost regardless of size or how long they've been operating. The most common one is treating compliance as a one-time "launch" task - a program written to pass a licensing review or open a bank account, then filed away while the business and the market keep evolving around it. A compliance program that doesn't grow with the business isn't really a program anymore; it's a historical document.
A second mistake is leaning entirely on automated tooling without a layer of human judgment. Automated systems are excellent at pattern detection, but they don't understand business context and don't always catch deliberate attempts to obscure activity. Businesses that skip human review of edge cases leave themselves exposed.
A third, and arguably the most dangerous, mistake is neglecting retrospective checks. Many businesses screen a client at onboarding but never re-check older wallet addresses as risk databases get updated - an address considered "clean" two years ago can turn out today to be tied to activity that only came to light later. And a fourth mistake, tied directly to my own background in alternative banking: many businesses don't understand how banking partners and EMI providers actually assess risk, and end up in front of their bank unable to explain, in terms the bank understands, how they manage their own risk. That's the fastest way to lose banking access altogether.
Building a Program That Grows With the Business
The best compliance program isn't one that covers every possible scenario on day one - that's impossible. The best program is one built to evolve: one that updates its risk assessment as new markets are entered, incorporates quality forensic data sources, and comes with documentation that lets you show a regulator, a bank, or an investor not just that you made the right call, but why you made it.
That's exactly the intersection where regulatory-financial knowledge meets the technical ability to read a blockchain. Knowing what the rules generally require isn't enough - you also need to be able to translate that into the operational reality of a business sending, receiving, and managing digital assets every day.
Let's Talk
If you're running a business that touches digital assets - whether you're an exchange, a fintech, an accounting firm serving crypto clients, or a traditional company that's started accepting digital payments - I'm happy to talk through what a compliance program suited to your actual size and risk profile would look like. This article is intended for general information only and isn't legal advice; any compliance program should be built around your specific circumstances, with qualified professionals involved. I'm available for an initial consultation to assess where your business stands today and what it would take to strengthen it going forward.
Facing a similar situation?
I'm glad to hear about your case and talk through the next steps — in complete confidence.