Crypto AML
Crypto AML combines customer due diligence, risk assessment, transaction monitoring, sanctions controls, suspicious-activity escalation and governance. Blockchain transparency can
Reading progress — saved on this device
Learning objectives
- Map an AML control framework from enterprise risk assessment to escalation and reporting.
- Understand how crypto typologies differ from conventional payment monitoring.
- Use blockchain analytics proportionately and with documented human review.
What the rule or control is
An AML programme starts with business-wide risk assessment: customers, products, geographies, delivery channels and transaction types. Controls then need to be calibrated to those risks and tested for effectiveness.
Crypto typologies include rapid layering across services/chains, scam proceeds, mixers, darknet exposure, ransomware, mule networks, sanctions evasion and abuse of bridges or DeFi. A transaction's presence on a public ledger helps trace flows but does not by itself prove criminality or knowledge.
Alert governance is critical. Firms should document thresholds, false-positive rates, analyst decisions, escalation criteria, suspicious-activity reporting and model changes. A vendor risk score should not be treated as a court finding.
Further analysis
Programme effectiveness also depends on independent testing and management information. Useful metrics include overdue reviews, alert-to-case conversion, suspicious-report quality, time to disposition, false positives and concentration of risk by product or corridor. These should be interpreted rather than optimised mechanically: a falling suspicious-report count could mean better controls, weaker detection or changing business mix. Senior management needs enough information to challenge assumptions, fund remediation and stop products whose risk cannot be controlled.
Control governance
Governance should also define who can approve high-risk relationships, who files or reviews suspicious-activity reports, how investigations are quality-assured and when the board is informed. Training should be role-specific: an investigator needs typology and evidence skills, while product teams need to understand how design choices alter laundering risk. New products should pass a financial-crime risk assessment before launch, with controls tested under realistic abuse scenarios rather than added only after incidents.
Decision framework
| Question | Why it matters |
|---|---|
| Jurisdiction | Rules differ by customer, entity, activity, location and regulator. |
| Legal classification | The same commercial label can cover legally different products or activities. |
| Evidence | Keep primary-source rules, transaction evidence and dated assumptions. |
| Change control | Re-check when legislation, guidance, product design or customer journey changes. |
Worked example and thought exercise
A wallet has indirect historical exposure to a sanctioned service several hops away. A vendor marks it 'high risk'. The firm should validate the exposure, amount, timing, attribution and applicable sanctions/AML obligations rather than automatically accusing the customer of wrongdoing.
Thought exercise: Which fact in the example would most change the legal, tax or compliance conclusion if it were different?
Common mistakes and practical workflow
- Outsourcing judgement entirely to a blockchain analytics vendor.
- Ignoring off-chain information such as customer occupation or payment purpose.
- Treating all mixer or privacy-tool exposure as identical.
- Measuring alert volume instead of control effectiveness.
Practical workflow
- Define the exact activity, asset, customer and jurisdictions.
- Find the current legislation/regulator or tax-authority source rather than relying on a secondary summary.
- Record the rule version/date and the facts used in the analysis.
- Document controls, evidence and any uncertainty or exceptions.
- Escalate to qualified legal, compliance or tax advice where the decision is material.
Primary sources to verify
- FCA AML/CTF regime and Financial Crime Guide.
- FATF virtual-asset/VASP risk guidance and 2026 targeted update.
- Applicable suspicious-activity reporting and sanctions legislation.
These references identify the primary authority or official guidance used for the educational framework. Always verify the live version before relying on a rule.
Knowledge checkpoint
- What is the main legal/compliance distinction in Crypto AML?
- Which facts or jurisdictional assumptions could change the answer?
- Why should primary-source dates be recorded?
- What is one common mistake that could create compliance or tax risk?
FAQs
❓ Is this lesson legal or tax advice?
No. It is educational. Rules depend on jurisdiction, facts and date; professional advice may be appropriate.
❓ Why does the review date matter?
Crypto regulation and tax guidance change quickly, so legal claims should be checked against current primary sources.
❓ Should a vendor or dashboard be treated as an authority?
No. Vendor outputs are evidence inputs; legal and tax conclusions should be grounded in applicable law and regulator or tax-authority guidance.
❓ What should I do when jurisdictions conflict?
Identify every relevant jurisdiction and obtain qualified advice rather than assuming one country's rules control globally.
Summary
Crypto AML combines customer due diligence, risk assessment, transaction monitoring, sanctions controls, suspicious-activity escalation and governance. Blockchain transparency can improve tracing, but analytics scores are evidence inputs rather than automatic legal conclusions. The disciplined approach is to separate labels from legal classification, record jurisdiction and date, preserve evidence, and verify current primary sources before acting.
Want this in a personalised order?
Take the crypto assessment and get a custom path of 10 modules matched to what you already know. Free, no card required.
Build my path →