BSA/FinCENUnited StatesCrypto

KYC and AML Requirements for Crypto in the United States

An expert guide to KYC, AML, and BSA compliance for cryptocurrency businesses operating in the United States under FinCEN, SEC, and CFTC regulatory frameworks.

Introduction to Crypto KYC Compliance in the United States

Few jurisdictions present a more tangled rulebook for cryptocurrency and digital asset businesses than the United States. There is no single crypto-specific statute. Federal and state rules overlap — and sometimes collide — for Virtual Asset Service Providers (VASPs).

At federal level, the Bank Secrecy Act (BSA) and the regulations that implement it, administered by the Financial Crimes Enforcement Network (FinCEN), are the core of KYC and AML duties for crypto firms. Depending on the digital assets in play, registration and compliance obligations from the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) can sit on top of that. For a foundational overview of identity verification principles, see our resource on what is KYC.

FinCEN and the Bank Secrecy Act (BSA)

Money Services Business (MSB) Classification

Since its 2013 guidance (FIN-2013-G001), FinCEN has treated exchangers and administrators of convertible virtual currencies as Money Services Businesses (MSBs). Most crypto exchanges, over-the-counter (OTC) desks, hosted wallet providers, and certain DeFi front-end operators fall inside the "money transmitter" definition in 31 CFR 1010.100(ff)(5).

MSB registration with FinCEN is mandatory and must be completed within 180 days of establishment. Failure to register is a federal crime under 18 U.S.C. 1960 and carries penalties of up to five years imprisonment.

Core BSA Compliance Obligations

Once registered, a crypto MSB must put in place a comprehensive AML program that includes:

  1. Written AML policies and procedures: Tailored to the specific risks of the crypto business.
  2. Designation of a compliance officer: A qualified individual responsible for day-to-day AML program management.
  3. Ongoing employee training: All relevant staff must receive regular AML training.
  4. Independent testing: The AML program must be audited by an independent party on a periodic basis.

Customer Identification Program (CIP)

FinCEN's CIP rule requires MSBs to collect and verify each customer's identity when a relationship is opened or a qualifying transaction is conducted. Required information includes:

  • Full legal name
  • Date of birth
  • Residential address
  • Government-issued identification number (SSN for US persons; passport number or equivalent for non-US persons)

Verification may be documentary (government-issued photo ID) or non-documentary (cross-referencing data against reliable databases). Many crypto companies use AI-powered verification platforms such as Joinble to automate document authentication, biometric matching, and database cross-checks — cutting onboarding friction while still meeting FinCEN requirements.

Suspicious Activity Reports (SARs)

Crypto MSBs must file SARs with FinCEN for any transaction of USD 2,000 or more that the business knows, suspects, or has reason to suspect involves funds derived from illegal activity, is designed to evade BSA reporting requirements, or has no apparent lawful purpose. SARs must be filed within 30 calendar days of initial detection and retained for five years.

Currency Transaction Reports (CTRs)

Transactions in currency exceeding USD 10,000 must be reported via CTRs. Whether CTRs apply to crypto-to-crypto transactions has been debated. FinCEN has proposed rules that would extend reporting to certain digital asset transactions. Firms should watch those developments closely.

The Travel Rule

FinCEN's Travel Rule (31 CFR 1010.410(f)) requires MSBs to collect, retain, and transmit specified information when funds transfers exceed USD 3,000. For crypto, that means that when a customer sends digital assets to an external wallet through a VASP, the originating institution must collect and pass along identifying information for both sender and recipient. Industry tools such as the TRISA and Travel Rule Universal Solution Technology (TRUST) protocols are emerging to support compliance.

State-by-State Licensing Requirements

The BitLicense and State Money Transmitter Licenses

Federal registration is only the start. Crypto businesses also face a maze of state-level licensing. New York's BitLicense, run by the New York Department of Financial Services (NYDFS), is the best-known state regime. It adds its own capital requirements, cybersecurity standards, and consumer protection duties, including detailed KYC and AML provisions.

Most other states require a money transmitter license (MTL). Requirements differ sharply:

  • Application fees range from a few hundred dollars to tens of thousands.
  • Surety bond requirements can reach USD 1 million or more in certain states.
  • Net worth minimums differ by jurisdiction.
  • AML program documentation must typically be submitted with the application.

A handful of states — including Montana and certain others — do not require money transmitter licenses. Wyoming has adopted crypto-friendly legislation that offers alternative regulatory paths for Digital Asset Business entities.

Practical Implications for KYC

State licensing authorities often examine an applicant's KYC controls on their own. A firm licensed in 40 states may go through 40 different examination cycles, each testing customer identification, transaction monitoring, and SAR filing. A centralized, automated KYC stack is essential. Joinble's identity verification platform helps crypto firms standardize onboarding across jurisdictions, applying consistent document verification and biometric checks regardless of which state's requirements are in play.

SEC and CFTC Considerations

When Is a Token a Security?

The SEC uses the Howey Test to decide whether a digital asset is an investment contract — and therefore a security. If a token is a security, the issuer, exchange, or broker-dealer that handles it becomes subject to SEC registration and compliance duties, including Regulation AML under the Securities Exchange Act and FINRA's KYC rules.

SEC-registered broker-dealers and alternative trading systems (ATSs) must run Customer Identification Programs under SEC Rule 17a-8 and FINRA Rule 3310, which fold in the BSA's CIP requirements and add further suitability and know-your-customer duties.

CFTC Oversight

Digital assets treated as commodities — Bitcoin and Ether most notably — fall under CFTC jurisdiction when they trade as derivatives (futures, options, swaps). Crypto derivatives platforms must register as Designated Contract Markets (DCMs) or Swap Execution Facilities (SEFs) and meet the CFTC's customer identification and AML requirements.

Even in the spot market, the CFTC keeps anti-fraud and anti-manipulation authority. It has brought enforcement actions against unregistered platforms that facilitated leveraged retail commodity transactions in crypto.

Sanctions Compliance and OFAC

All US persons and businesses, crypto firms included, must comply with the sanctions programs administered by the Office of Foreign Assets Control (OFAC). That means screening customers and wallet addresses against the Specially Designated Nationals (SDN) list and blocking or rejecting transactions that involve sanctioned persons, entities, or jurisdictions.

OFAC has added cryptocurrency wallet addresses to the SDN list and issued guidance making clear that sanctions obligations apply equally to virtual currency transactions. Crypto firms should put wallet screening tools alongside traditional identity verification so coverage is complete.

Building a Compliant Crypto KYC Program

An effective KYC program for a US crypto business should include:

  • Tiered verification: Risk-based thresholds that apply lighter verification for low-value transactions and full CIP for higher-risk or higher-value activity.
  • Document authentication: Automated validation of government-issued IDs using AI-driven optical character recognition and fraud detection.
  • Biometric verification: Liveness detection and facial matching to prevent identity spoofing.
  • Blockchain analytics: On-chain monitoring to identify transactions involving high-risk wallets, mixers, or darknet markets.
  • Ongoing monitoring: Continuous transaction surveillance and periodic re-verification of customer information.

Joinble's AI-powered identity verification slots into crypto onboarding flows, combining document verification, biometric matching, and sanctions screening in a single API call. Exchanges and wallet providers can keep the user experience light without dropping regulatory compliance.

FinCEN, the SEC, the CFTC, and state regulators have all stepped up enforcement against crypto businesses with weak KYC and AML controls. Notable actions include multimillion-dollar penalties against exchanges that failed to register as MSBs, operated without state licenses, or did not file SARs. The Department of Justice has also brought criminal charges against individuals who facilitated money laundering through unregistered crypto platforms.

Those enforcement patterns show why compliance infrastructure belongs in from day one, rather than being bolted on after scrutiny starts.

FAQ

Does every crypto business in the US need to register with FinCEN?

Most crypto businesses that exchange, transmit, or custody virtual currencies on behalf of customers qualify as Money Services Businesses and must register with FinCEN. Some exceptions can apply — users who transact solely for their own account, or software developers who create non-custodial protocols, for example. FinCEN reads the MSB definition broadly, so firms should seek legal counsel. For more on identity verification basics, see our what is KYC guide.

What is the difference between the BitLicense and a state money transmitter license?

The BitLicense is New York-specific and covers virtual currency business activity conducted with New York residents. It adds requirements beyond a standard money transmitter license, including cybersecurity mandates and consumer protection disclosures. In most other states, crypto businesses apply for a general money transmitter license that covers fiat and virtual currency transmission.

How does the Travel Rule apply to cryptocurrency transactions?

Under FinCEN's Travel Rule, a crypto MSB that transmits funds worth USD 3,000 or more on behalf of a customer must collect identifying information for sender and recipient and pass it to the next institution in the payment chain. Industry protocols such as TRISA are being built so VASPs can exchange that data in a privacy-preserving way.

Can crypto companies use automated KYC solutions to satisfy FinCEN requirements?

Yes. FinCEN does not prescribe specific verification methods. Firms may use documentary and non-documentary approaches. AI-powered identity verification platforms that perform document authentication, biometric matching, and database cross-referencing are widely used and accepted, provided they deliver reliable results and keep proper audit trails.

What happens if a crypto firm operates without proper KYC and AML controls?

Consequences include FinCEN civil money penalties, state enforcement actions (including license revocation), SEC or CFTC charges if securities or derivatives are involved, and potential criminal prosecution under 18 U.S.C. 1960 for operating an unlicensed money transmitting business. Penalties have reached hundreds of millions of dollars in recent cases.

Automate your compliance with AI Agents

Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.

Book a demo