Skip to content
← Back to the list

Crypto Exchange Compliance Checklist for Founders (KYC, KYB, AML Ops)

Crypto Exchange Compliance Checklist for Founders (KYC, KYB, AML Ops)

Launching without a working compliance stack is how exchanges lose banks, licenses, and sleep. KYC checks who a user is, KYB checks a company and its owners, and AML is the ongoing watch for dirty money plus reporting. Use this crypto exchange compliance checklist to map entity and market risk, pick a KYC/KYB/AML stack, wire monitoring and Travel Rule, diligence vendors, then run a hard go/no-go before public trading.

TL;DR / Quick insight: Write a one-page risk map (entity, geos, product, fiat rails) before you buy tools. Separate retail KYC from corporate KYB (UBO to real people). Run fiat and crypto monitoring with escalation to a named compliance owner. Treat Travel Rule as a launch blocker in regulated markets. Do not open public trading until the go/no-go list below is green.

Most SERP guides sell a KYC vendor demo or a CCO exam. Founders need a pre-launch sequence. Plain terms: a VASP (virtual asset service provider) or EU CASP (crypto-asset service provider) is the regulated operator; white-label software can plug in vendors, but you still own policies, licensing, and reports. Not legal advice – engage counsel per market.

1. How to map your entity, markets, and product risk

Workflow diagram mapping crypto exchange entity, markets, and product risk tiers

Start on paper. If you cannot describe where money and data move, you cannot pick the right tools.

  1. Name the legal entity that will operate the exchange or exchanger.
  2. List target user countries and geos you will refuse at signup.
  3. Define the product: spot CEX, instant exchanger, P2P, custody, or a mix.
  4. Mark fiat on/off-ramps and which partners touch customer funds.
  5. Write a one-page risk map: who you serve, which assets move, where cash enters and exits.

Do treat that page as the brief for counsel and vendors. Don’t promise a “global launch” while monitoring only covers one corridor. Pick a licensing path with counsel (VASP, CASP, MSB, or local equivalent) and write what you may legally offer before the first public customer – do not invent timelines.

2. Choose the KYC / KYB / AML stack

Comparison table UI for choosing KYC, KYB, and AML stack modules

These three layers solve different jobs. Mixing them into one vague “we do KYC” line is a common failure.

Layer What it checks When it runs
KYC Natural person: ID, liveness, address where required, sanctions/PEP Onboarding and refresh
KYB Legal entity: registry, directors, UBO (ultimate beneficial owner) to natural persons Corporate accounts and partners
AML / KYT Ongoing rules + blockchain analytics (KYT = know-your-transaction) + sanctions Continuously after signup

Common staging: identity + perpetual KYC → risk class and EDD (extra checks for high-risk/PEP/UBO) → ongoing KYT. Retail tiers: light Tier 1 → ID + liveness + address for Tier 2 → source-of-funds for Tier 3. UBO thresholds often cited around 10%+ – confirm local law.

Do write CIP/CDD policy so ops know when to escalate. Don’t reuse the retail KYC form for institutions. More: KYC, KYB, and AML basics.

3. Wire monitoring, SAR escalation, and the audit trail

AML monitoring dashboard showing SAR escalation queue and audit trail

Signup identity checks are not AML. AML watches flows after signup and documents why you acted.

  1. Monitor fiat and crypto legs, not crypto alone.
  2. Add blockchain analytics for direct and indirect exposure (Chainalysis 2026: indirect thresholds can be ~10–20× looser for fraud-like categories).
  3. Open a case queue: every alert gets an owner, evidence, and deadline.
  4. Escalate to a named compliance owner / MLRO (money laundering reporting officer) who can freeze or file.
  5. Document the SAR/STR path (suspicious activity report) per market with counsel.
  6. Keep an exportable audit trail: who decided what, when, on which evidence.

Workflow: Alert → case → review → escalate or close → file SAR/STR if required → retain records (EU Transfer of Funds rules commonly cite a 5-year baseline).

Chainalysis reports that nearly half of orgs onboarded in 2026 run alerting strictness that was top ~10% in 2020 – industry pressure, not a legal minimum. Do name one accountable human before go-live. Don’t launch withdrawals with “we will tune alerts later.” Related: customer dispute handling.

Travel Rule is ops. Under FATF Recommendation 16, VASPs must obtain, hold, and transmit originator/beneficiary info for qualifying transfers. FATF often cites a USD/EUR 1,000 de minimis – jurisdictions differ. EU Reg (EU) 2023/1113 applies from 30 December 2024: CASPs must send originator/beneficiary details; for self-hosted addresses over €1,000 they must assess client ownership/control. Use a messaging layer plus counterparty VASP due diligence – the chain alone does not carry that data.

Do test sample VASP↔VASP flows before public transfers. Don’t treat Travel Rule as a post-MVP patch where it is already required.

4. Vendor and payment-partner due diligence checklist

Vendors supply tooling. The licensed operator stays accountable if a vendor miss leads to bad onboarding or a skipped report.

  • KYC: document types, liveness, sanctions/PEP, data residency, exit plan
  • KYB: registry sources, UBO tracing depth, re-screen cadence
  • KYT / analytics: asset coverage, alert categories, audit export
  • Travel Rule network: peer reach, fail-open vs fail-closed behavior
  • Custody / wallets: key roles, withdrawal controls, incident logging
  • Banking / EMI / payments: written AML acceptance or a contingency
  • Contracts: audit rights, outage SLA, data ownership, vendor switch path

A branded stack can speed modules – still verify included versus bring-your-own KYC/AML. Explore White Label Exchange, then keep operator policies in your own repo of record.

Do finish DD before soft-launch marketing. Don’t assume “our software partner is licensed” means you are licensed.

5. Run the pre-launch compliance go/no-go checklist

Public trading starts only when must-haves are yes – or residual gaps are accepted in writing with owners and compensating controls.

Must be YES before public trading

  • Entity + target markets documented; counsel engaged
  • Licensing/registration path written (even if pending)
  • Retail KYC live (ID, liveness, address where required) + sanctions/PEP
  • KYB path for corporate accounts, liquidity partners, and VASP counterparties
  • Risk scoring + EDD triggers documented
  • Monitoring covers fiat and crypto; blockchain analytics connected
  • Travel Rule tested on sample VASP↔VASP flows (if in scope)
  • Self-hosted wallet procedure defined where required (EU: ownership check over €1,000)
  • Case queue + named compliance owner; SAR/STR path known
  • Audit trail exportable: decision, actor, timestamp, evidence
  • Record retention matches local law (note EU 5-year baseline)
  • KYC, KYT, Travel Rule, custody, and payment vendors DD completed
  • Banking/EMI/payment partners accepted your AML program (or contingency)
  • Board/founder sign-off; open gaps have owners and dates

Go: all must-items yes, or written exceptions with controls. No-go: no sanctions screening, no named compliance owner, no monitoring on withdrawals, or Travel Rule required but untested. Industry blogs often cite 1 July 2026 as a hard end for many MiCA grandfathering windows – check your NCA.

Do walk this list in a founder + compliance meeting. Don’t open ads while red items “will be fixed next sprint.”

What to do next

  1. Finish the one-page entity / markets / product risk map.
  2. Book counsel for the licensing path in each launch market.
  3. Choose KYC and KYB vendors; write tier limits + EDD triggers.
  4. Stand up monitoring → case → escalate → file/close with an audit export test.
  5. Run the go/no-go list; soft-launch only after greens.

More playbooks: White Label Exchange blog. For a white-label stack while you own compliance ops, start at whitelabelexchange.io.

Material reviewed: White Label Exchange Editorial.
Data note: EU TFR facts from EUR-Lex on Reg (EU) 2023/1113 (applies 30 Dec 2024; self-hosted ownership checks over €1,000; 5-year retention). Alerting maturity from Chainalysis Compliance Benchmark 2026. MiCA grandfathering cited as reported industry timing (verify with NCA). Wordstat unavailable; no fabricated counts. Not legal or investment advice. Notes: 16 July 2026.

Frequently asked questions

Do white-label exchanges include KYC?

Many integrate KYC/AML vendors or hooks, but the operator still owns policies, licensing, SAR filings, and vendor oversight. Confirm included versus bring-your-own before you sign.

What AML tools do crypto exchanges use?

Typical stack: identity verification (Sumsub/Onfido/Jumio class), sanctions/PEP screening, blockchain analytics/KYT (Chainalysis/Elliptic class), Travel Rule messaging, and case management. Examples, not endorsements.

What is the difference between KYB and KYC?

KYC verifies a natural person. KYB verifies a legal entity plus directors and UBOs down to real people. Retail uses KYC; corporates and VASP counterparties need KYB.

What is the Travel Rule in plain terms?

When you send crypto to another regulated provider, you also send verified sender/receiver info through a messaging layer. Thresholds depend on jurisdiction – FATF often cites about USD/EUR 1,000; EU TFR for CASPs is stricter in scope. Confirm local law.

Can we launch without Travel Rule and add it later?

Risky where already required. Prefer testing VASP↔VASP messaging before public transfers. Retrofitting live platforms leaves audit gaps.

Who is liable if a compliance vendor fails a check?

Usually the licensed operator. Keep vendor DD, audit rights in contracts, and a documented escalation path.

What is a minimum compliance team at launch?

At least a named compliance owner or MLRO with real authority, plus trained ops who can open cases and escalate. Team size scales with volume.