Image: Chainalysis — total illicit cryptocurrency value received by year, 2020 through 2024, including the 51.3 billion dollar lower-bound estimate for 2024

A crypto compliance program is the documented system a virtual asset business uses to identify customers, monitor transactions, screen sanctions exposure, file reports, and prove all of it to a regulator. It is not a folder of policies. It is the combination of written procedures, named accountable people, configured software, and a paper trail showing the procedures actually ran. When an examiner walks in, they do not ask whether you have a policy — they ask you to show the last twelve months of alerts, dispositions, and filings that the policy produced.

Most teams get this backwards. They buy tools first, write policies to match the tools, and discover during their first exam that nothing connects the two. This guide walks through what a program actually contains, the order to build it in, how the major vendor platforms map to each component, and the failure patterns examiners cite most often. It is written for the person who has just been told "you own compliance now" at an exchange, a wallet company, a payments firm touching stablecoins, or a fund — whether that is a dedicated officer or a founder wearing the hat.

Quick solution

If you need a defensible crypto compliance program and you are starting from little or nothing, do this, in this order:

  1. Write the risk assessment first. Score your products, customer types, geographies, and asset mix before buying anything. Our guide to crypto AML risk assessment covers the scoring method; the output of that document decides everything below.
  2. Name one accountable officer. A single person with authority to freeze activity and file reports, named in writing, approved by the board or its equivalent.
  3. Stand up KYC/KYB at onboarding. Identity verification, beneficial ownership for entities, and initial risk-rating of every customer. See our comparison of KYC and KYB providers for digital assets.
  4. Turn on sanctions and transaction screening from day one of the program, not day ninety. Wallet screening against OFAC SDN-listed addresses and jurisdiction exposure at deposit and withdrawal.
  5. Deploy transaction monitoring with a documented rule rationale. Every rule threshold traceable back to a risk in step 1.
  6. Write the reporting and recordkeeping procedure. Who drafts a suspicious activity report, who approves it, the filing deadline clock, and the five-year retention plan.
  7. Schedule independent testing before a regulator schedules it for you. An annual review by someone who does not own the program.

Everything else in this article explains how to do each step without creating the gaps examiners find.

Regulators across major jurisdictions converge on the same core structure, usually described as the pillars of an anti-money-laundering program. For a virtual asset service provider, the pillars translate into concrete crypto-specific work:

Internal policies, procedures, and controls. The written documents describing how you onboard customers, rate risk, monitor transactions, screen sanctions lists and wallet addresses, handle the Travel Rule, and file reports. The test of a good procedure is that a new hire could execute it without asking anyone. The test of a bad one is the phrase "as appropriate" doing all the work.

A designated compliance officer. One named person, with real authority and access to the board. Regulators repeatedly fault programs where the officer role is split across three part-time people or held by someone who also owns revenue targets, because that person cannot credibly halt a large customer's activity.

Ongoing training. Documented, role-specific, and dated. Support agents need to recognize structuring behavior in chat; engineers need to know why a screening bypass is a reportable event, not a hotfix.

Independent testing. An annual review of the program by internal audit, an external firm, or a qualified consultant who does not report to the compliance officer. The finding letter and remediation tracker from this review are among the first documents an examiner requests.

Customer due diligence and beneficial ownership. Identity verification calibrated to risk, ownership unwrapping for corporate customers, and — critical in crypto — counterparty diligence on other VASPs you exchange funds with, covered in our guide to VASP due diligence.

On top of the pillars, crypto adds obligations that fiat-only institutions do not carry: wallet address screening, on-chain exposure tracing through analytics platforms, and Travel Rule data exchange when transfers cross the applicable threshold. A program document that never mentions blockchain analytics or the Travel Rule was copied from a bank template and examiners recognize it immediately.

Why the program scope keeps widening

The scale of what programs must catch is not shrinking. Chainalysis's 2025 Crypto Crime Report estimated 51.3 billion dollars in illicit cryptocurrency value received during 2024 as a lower bound, with the firm's historical revision pattern suggesting the final figure would land considerably higher as more illicit addresses are identified. Two structural shifts inside that number matter for program design.

Chainalysis chart showing the share of on-chain crime activity by asset type, with stablecoins accounting for the majority

Image: Chainalysis — illicit transaction volume by asset type, showing stablecoins carrying the largest share of on-chain criminal activity

First, the asset mix moved. Stablecoins now carry the majority of illicit transaction volume, displacing Bitcoin. A monitoring rule set written in 2021 that concentrates on BTC flows systematically under-weights where the risk actually sits today. Your program's asset-risk table needs a review cycle, not a publication date.

Second, the regulatory perimeter moved. The OECD's Crypto-Asset Reporting Framework began taking effect across early-adopter jurisdictions, pulling tax-relevant transaction reporting into scope for exchanges that previously treated tax as the customer's problem. Chainalysis's August 2026 analysis of 2025 crypto flows found that only about 63.8 billion dollars — roughly 14 percent of measurable flows — moved through CARF-covered channels in the first wave, a figure regulators openly intend to grow by expanding coverage. If your roadmap does not include transaction-level reporting capability, you are planning for the perimeter of 2023.

Chainalysis pie chart of 2025 crypto flows by Crypto-Asset Reporting Framework coverage, showing 63.8 billion dollars, about

Image: Chainalysis — 2025 crypto flows split by CARF reporting coverage, with covered channels carrying about 14 percent of measured volume

The same analysis quantified why tax authorities care: Chainalysis measured roughly 457.5 billion dollars in potentially taxable crypto activity across gains, income, and payments in 2025, distributed unevenly across regions. Programs at exchanges serving CARF jurisdictions should treat reporting-data quality — clean customer identifiers tied to clean transaction records — as a compliance control, because it is about to be examined like one.

Chainalysis sankey diagram of potentially taxable crypto activity in 2025, totaling about 457.5 billion dollars across

Image: Chainalysis — potentially taxable crypto activity in 2025 by category and region, totaling approximately 457.5 billion dollars

More in Guides

Build order: the sequence that avoids rework

Teams that build in the wrong order pay for it twice. The sequence below reflects how the components depend on each other.

Phase one — risk assessment and governance (weeks 1–4). The enterprise-wide risk assessment is the root document. Products, customer segments, geographies, delivery channels, and asset types each get inherent risk scores; controls get effectiveness ratings; the residual risk decides your tooling budget and rule aggressiveness. Then the governance shell: officer appointment, board approval of the program charter, and a policy calendar.

Phase two — onboarding controls (weeks 3–8, overlapping). KYC/KYB vendor selection and integration, customer risk-rating model, and enhanced due diligence triggers. The risk-rating model must consume the categories from phase one — if the risk assessment says exposure to high-risk jurisdictions is your top threat, the customer risk model must weight geography accordingly, or an examiner will read the two documents as unrelated.

Phase three — screening and monitoring (weeks 6–12). Sanctions screening on names at onboarding and wallet addresses at every deposit and withdrawal — our review of crypto sanctions screening tools compares the main options. Then behavioral transaction monitoring: rules for structuring, rapid movement through the platform, mixer and high-risk-service exposure, and peel-chain patterns. Every rule gets a one-paragraph rationale document; unexplained thresholds are the single most common monitoring finding.

Phase four — reporting, testing, training (weeks 10–16). Suspicious activity reporting workflow with the deadline clock documented, recordkeeping retention, the training calendar, and the engagement letter for the first independent test. Do not let the independent test slip past month twelve.

The phases overlap deliberately. What cannot overlap is phase one and anything else: tooling bought before the risk assessment exists tends to define the program instead of serving it.

How the major platforms map to program components

Because no single public source compares the major compliance platforms by which program component they actually cover, we compiled one from vendor documentation, regulator-published enforcement material, and the categories used across our own vendor reviews. The table shows where each platform is strongest inside a program, not a ranking — most real programs run two or three of these side by side.

PlatformStrongest program componentBlockchain analytics depthKYC/KYB onboardingBehavioral monitoringTypical buyer
ChainalysisOn-chain exposure tracing and investigationsVery deep, largest attribution datasetNo (partner integrations)Via KYT alerts on exposureExchanges, government, banks
EllipticWallet and VASP screeningDeep, strong cross-chain coverageNoExposure-based alertsExchanges, fintechs, banks
TRM LabsRisk-scored screening and investigationsDeep, fast chain expansionNoExposure and behavioral signalsExchanges, fintechs, agencies
ComplyAdvantageName screening and adverse mediaLimited on-chainScreening side of onboardingRules-based AML monitoringFintechs, payments, smaller VASPs
Merkle ScienceBehavioral rule monitoringModerate, behavior-focusedNoDeep, configurable rule engineExchanges, Web3 firms
SumsubFull KYC/KYB onboarding flowVia integrationsDeep, document and biometricOnboarding-fraud signalsExchanges, wallets, fintechs

Two practical notes on reading it. The blockchain analytics platforms — compared in detail in our guide to blockchain analytics for compliance — do not do identity onboarding, and the onboarding vendors do not trace funds on-chain, so "which vendor should we buy" is usually a category error; you are assembling a stack, and our overview of crypto AML compliance software covers the full stack view. Second, every platform in the table will happily sell you more modules than your risk assessment justifies. The assessment, not the sales call, decides the configuration.

A program can have every document and still fail its exam on calibration. The two charts below illustrate why static rule sets decay.

Chainalysis chart of total stolen fund volumes taken from personal wallets by year and by asset, showing growth in personal

Image: Chainalysis — stolen fund volumes from personal wallets by year and asset, from the 2025 mid-year crypto crime update

Chainalysis's July 2025 mid-year update showed personal wallet compromises growing as a share of total stolen funds, with attackers increasingly targeting individual holders across multiple asset types rather than only service infrastructure. For an exchange program, that shifts what "suspicious deposit" looks like: victim funds arriving from drained personal wallets, moving fast, often in assets your 2022-era rules under-monitor. Rules tuned only for service-hack laundering patterns miss the deposit-side signature of wallet-drainer proceeds.

Chainalysis chart of cumulative value stolen from crypto services by year, with 2025 running ahead of every prior year at

Image: Chainalysis — cumulative value stolen from services by year, showing 2025 outpacing prior years at the same point in the calendar

Meanwhile the same update showed 2025's cumulative value stolen from services running ahead of every prior year at the mid-year mark, driven substantially by the February 2025 Bybit theft — a reminder that counterparty exposure to a breached service can materialize in your deposit flow within hours of an incident. A calibrated program has a documented playbook for incident-driven screening updates: who adds the newly published attacker addresses to the screening set, on what timeline, and how the action is logged. Pair that with continuous transaction monitoring tuned for exchange flows and quarterly rule-performance reviews — alert volume, true-positive rate, and rules that have never fired — and the calibration section of your exam becomes routine instead of existential.

Common situations and what to do

Most teams arrive at this problem from one of three directions.

"We are a newly licensed exchange and our first examination is scheduled in six months." Work the build order above, but front-load the paper trail: examiners weight evidence of operation over elegance of design. Ninety days of real alert dispositions, a filed report or a documented decision not to file, and one completed training session beat a beautiful policy suite with no execution history. Commission the independent test early enough that you can show remediation in progress — a finding you found is a strength; a finding they find is a finding.

"We are a fintech adding stablecoin payments to an existing money-transmission business." Your existing AML program is a real asset, but it does not extend automatically. Amend the risk assessment for on-chain exposure, add wallet screening and analytics coverage, and update the monitoring rules for crypto-native typologies — the fiat rules will not catch mixer exposure or peel chains. Your regulator will expect the program amendment to be board-approved before launch, not after.

"We are a five-person startup and cannot afford a compliance team." You can afford a program; you cannot afford a department, and regulators know the difference. One founder formally designated as officer, a risk assessment you write yourselves using a published methodology, one onboarding vendor and one screening vendor on startup pricing, and an external consultant for the annual test. What you cannot skip is the writing-it-down part — an undocumented control does not exist at exam time.

The same failure patterns recur across public enforcement actions against crypto firms:

  • Growth outran the program. Customer count multiplied while the compliance team and alert-handling capacity stayed flat, producing months-deep alert backlogs — the single most cited operational failure.
  • The program was written but never operated. Policies existed; nobody could produce dispositions, training records, or filed reports matching them. Regulators treat a paper program as no program with intent.
  • Screening had known gaps that were logged and ignored. Engineering tickets acknowledging a bypassed screening path, open for months, feature prominently in penalty documents. An internally documented gap without a remediation clock is an admission.
  • Jurisdictional exposure was pushed through instead of decided. Serving users from prohibited jurisdictions via known workarounds, with internal chatter proving awareness, converts a compliance failure into a candidate for individual liability.

Every one of these is cheaper to prevent than the smallest of the fines associated with it.

Frequently asked questions

What is a crypto compliance program?

It is the documented system a crypto business uses to meet anti-money-laundering, sanctions, and reporting obligations: written policies and procedures, a designated compliance officer, customer due diligence, transaction and wallet screening, suspicious activity reporting, staff training, and periodic independent testing, together with the records proving all of it operates.

How much does it cost to run one?

For a small VASP, a credible floor is one full-time officer, an onboarding vendor and a screening or analytics vendor (each commonly five to six figures annually depending on volume), plus an annual independent review. Costs scale with transaction volume, jurisdiction count, and product risk — which is why the risk assessment precedes the budget.

Do we need blockchain analytics if we already have a traditional AML vendor?

Almost certainly yes if you custody or move crypto. Traditional vendors screen names and fiat patterns; they cannot see that a deposit is four hops from a sanctioned mixer. Wallet-level exposure tracing is the crypto-specific control examiners now expect as standard.

Who should the compliance officer report to?

To the chief executive or the board, not to a revenue-owning executive. Examiners read the reporting line as a proxy for whether the officer can actually stop profitable activity, and enforcement actions have specifically criticized structures where compliance reported into sales or growth functions.

How often should the program be updated?

Review the risk assessment and monitoring rules at least annually, and after any material change: a new product, a new jurisdiction, a new asset listing, or a major public incident that changes your threat model. Date every revision — an examiner reading a risk assessment stamped three years ago has already drafted the finding.

Sources

  • Chainalysis, "2025 Crypto Crime Report" (February 2025) — 51.3 billion dollar lower-bound estimate for 2024 illicit value received and the shift of illicit volume toward stablecoins.
  • Chainalysis, "2025 Crypto Crime Mid-Year Update" (July 2025) — record cumulative value stolen from services at mid-year and the growth of personal wallet victimization.
  • Chainalysis, "Crypto Flows, Taxable Activity, and CARF Coverage in 2025" (August 2026) — 63.8 billion dollars of 2025 flows inside CARF-covered channels and roughly 457.5 billion dollars in potentially taxable activity.