What Is Crypto Compliance? FATF, FinCEN, and How It Works
Crypto compliance is the system that keeps a digital-asset business licensed and bankable while staying clear of prosecution. The pressure arrived in 2026: illicit crypto addresses received at least $154 billion in 2025, a record, and regulators now expect any firm handling that value to meet the same detection standards banks do.
The system works in three layers: FATF sets the global standard, national bodies like FinCEN enforce it by jurisdiction, and software automates the daily work.

TL;DR
- Crypto compliance now runs on three layers: global standards, national enforcement, and the software that does the daily work.
- FATF sets the worldwide AML rules; FinCEN enforces them in the US and the EU's AMLA does the same across Europe.
- Since 2025, these rules reach stablecoin issuers too, alongside exchanges and transfer platforms.
- KYC, blockchain analytics, and Travel Rule tools handle the monitoring no compliance team could manage by hand.
Why Is Crypto Compliance Harder in 2026 Than Ever Before?
Until 2025, crypto obligations stopped at the border. A firm could hold a license in one country, serve users in fifty others, and face enforcement that rarely caught up.
That changed when the numbers became impossible to ignore. Criminal money on-chain is no longer a rounding error. Chainalysis, the blockchain analytics firm whose data regulators cite, put that figure at roughly the annual GDP of Slovakia, and traced a 162% jump over the prior year. Regulators moved once the scale became clear.
The number that changed the rulebook: Stablecoins carried 84% of that illicit volume, even though illicit activity stays below 1% of all crypto transactions. The asset built for payments now moves most of the dirty money too, which is exactly why stablecoin issuers face bank-style rules.
The legal response followed the data. The enforcement pattern was set in January 2025: the exchange BitMEX was sentenced to a $100 million fine for violating the Bank Secrecy Act, a banking offense applied to a crypto company. It was not an isolated case: prosecutors have brought the same Bank Secrecy Act charge against KuCoin, OKX, and Binance.
What Is FATF and How Does It Set the Global AML Baseline?
The Financial Action Task Force (FATF) is the intergovernmental body that writes the anti-money-laundering standards countries in the FATF network are expected to adopt. FATF sets the direction; national regulators turn it into enforceable law.
Countries that ignore those standards end up on grey lists, making it harder to access international banking.
Its core crypto standard is Recommendation 15. It tells countries to license virtual asset service providers (VASPs, the FATF term for exchanges, custodial wallets, and transfer platforms) and to monitor them for laundering risk.
The best-known piece is the Travel Rule: identifying data about the sender and recipient must accompany a crypto transfer, just as it does with an international wire transfer.
In its June 2025 Targeted Update, FATF counted 99 jurisdictions with Travel Rule legislation passed or in progress.
Passing a law and enforcing it are different things. Compliant firms still hit friction when they must send Travel Rule data to a counterpart in a jurisdiction still catching up, a problem the industry calls the sunrise issue.
Scope check: FATF's 2026 updates pull more stablecoin arrangements and DeFi (decentralized finance) products under the VASP definition. A product that felt out of scope in 2024 may not be today.
What Does FinCEN Require From Crypto Businesses in the US?
FinCEN, the Financial Crimes Enforcement Network, is the US Treasury bureau that enforces the Bank Secrecy Act (BSA), the law requiring financial institutions to help detect and prevent money laundering.
Where FATF sets non-binding global standards, FinCEN turns the US requirements into binding rules and enforces them itself.
Firms that accept or transmit crypto for US customers qualify as money services businesses (MSBs) under FinCEN's regulatory framework, a category that now includes exchanges, transfer platforms, and stablecoin issuers. MSB classification triggers five duties:
- Register with FinCEN as a money services business.
- Run a written AML program with a named compliance officer who owns it.
- Verify customers through KYC (know your customer) checks: ID documents, liveness, source of funds for high-risk users.
- File suspicious activity reports (SARs) when a transaction looks illicit, within 30 days of detection.
- Screen against OFAC sanctions lists before funds move. OFAC (Office of Foreign Assets Control) is the US Treasury unit that publishes the names of sanctioned individuals, entities, and countries.
Those five duties applied to existing categories. In 2025, the GENIUS Act added a new obligation, effective January 2027. It created the first US federal framework for payment of stablecoins; the dollar-pegged tokens designed to hold a fixed value.
Under the GENIUS Act, permitted stablecoin issuers will be classified as financial institutions under the BSA. Treasury has since proposed the implementing rules covering AML programs, SAR filing, and sanctions compliance. Once the Act takes effect no later than January 18, 2027, issuing a dollar-pegged token will carry the same paperwork as opening a bank.
The cost of ignoring that paperwork is documented. BitMEX served US users from 2015 to 2020 while asking for little more than an email address. The $100 million sentence in January 2025 closed the case and set the reference point prosecutors cite today.
How Does the EU Regulate Crypto Through AMLA, MiCA, and the Travel Rule?
Europe replaced its patchwork of national supervisors with one central system, defined by three instruments that work together.
AMLA (Anti-Money Laundering Authority) is the EU's new central supervisor, based in Frankfurt. It started operations in summer 2025 and absorbed AML mandates from the European Banking Authority in January 2026. From 2028, AMLA will directly supervise around 40 high-risk cross-border institutions. The group explicitly includes crypto-asset service providers operating across multiple member states. For everyone else, AMLA coordinates national supervisors, so shopping for the least strict regulator becomes much harder to sustain.
AMLR (Anti-Money Laundering Regulation), Regulation (EU) 2024/1624, is the single rulebook. It applies directly in all 27 member states from July 10, 2027, replacing 27 different national interpretations with one set of due diligence requirements.
MiCA and the Travel Rule. MiCA (Markets in Crypto-Assets Regulation) governs who may offer crypto services in the EU. The Transfer of Funds Regulation adds the Travel Rule with no minimum threshold, meaning a one-euro transfer carries the same data obligations as a one-million-euro transfer.
Layer | Who | Job | Key date |
|---|---|---|---|
Global standard | FATF | AML baseline, Travel Rule | Ongoing assessments |
US enforcement | FinCEN | BSA duties for MSBs and stablecoin issuers | GENIUS rules in progress |
EU enforcement | AMLA + AMLR | AMLA supervises; AMLR is the single rulebook | AMLR applies July 2027; AMLA direct supervision 2028 | AMLR July 2027; direct supervision 2028 |
What Tools Do Crypto Businesses Use for Compliance?
No compliance officer reads millions of transactions by hand, any more than an airport screens luggage by opening every bag. What makes both systems work is a detection layer that sits between the flow and the threat.
Three tools cover the work:
Tool category | What it does | Who provides it |
|---|---|---|
KYC (know your customer) | Confirms users are who they claim: ID documents, liveness detection, sanctions screening at onboarding | Sumsub, Jumio, Onfido |
Blockchain analytics | Traces funds across chains and scores wallet risk. A background check run on the money itself. Flags deposits from sanctioned mixers before they settle | Chainalysis, TRM Labs, Elliptic |
Travel Rule messaging | Carries sender and recipient data alongside the on-chain transfer, so both sides of a transaction can be traced and verified | Notabene, Sygna, VerifyVASP |
FATF itself credits Chainalysis and TRM Labs as contributors to its global implementation review. Coming from a body that cannot fine anyone, that credit signals which vendors the regulators lean on themselves.
How Do You Set Up a Crypto Compliance Program That Passes Regulatory Review?
Across the major jurisdictions, regulators check for the same things.
Six steps, in order:
Step | Action | What the regulator checks |
|---|---|---|
1. Map exposure | Identify where your users are and which licenses that triggers | Jurisdictional coverage, no blind spots |
2. Write the AML policy | Document the program and name a compliance officer who owns it | Written program + named accountable person |
3. Deploy risk-tiered KYC | Fast flow for low-risk users; enhanced due diligence for high-risk ones | CDD (customer due diligence) standards met, with tiers matched to each user's risk |
4. Monitor continuously | Pair blockchain analytics with alert rules tuned to your product | Suspicious activity caught and acted on, with alerts that trigger a response |
4. Monitor continuously | Pair blockchain analytics with alert rules tuned to your product | Suspicious activity caught and acted on, with alerts that trigger a response |
5. Report and retain | File SARs on time; keep records for as long as your jurisdiction requires | SAR timeliness and record completeness |
6. Audit yearly | Review and update: the requirements changed every year from 2024 through 2026 | Program currency, with each control reviewed against the latest rules |
For companies whose core business is not compliance, one option is to work with infrastructure that already carries these controls. Some regulated card-to-crypto on-ramps integrate KYC, transaction monitoring, and sanctions screening at the payment layer, Mercuryo among them.
The regulatory environment will keep moving. AMLA begins direct supervision in 2028, the GENIUS Act's implementing rules are still being written, and FATF reviews jurisdictions on an ongoing cycle. A compliance program needs constant upkeep to hold against a standard that keeps rising.
Frequently Asked Questions
What is FinCEN in crypto?
FinCEN is the US Treasury bureau that enforces the Bank Secrecy Act. It requires crypto firms serving US users to register as money services businesses, run AML programs, verify customers, and file suspicious activity reports.
What does FATF require for crypto businesses?
FATF requires countries to license and supervise virtual asset service providers, and to apply the Travel Rule: sender and recipient data must accompany transfers above a set threshold that FATF recommends at USD/EUR 1,000. Some jurisdictions go further. The EU applies the rule with no minimum threshold at all.
Which tools do compliance teams use?
Three: KYC providers like Sumsub for identity checks, blockchain analytics firms like Chainalysis and TRM Labs for transaction monitoring, and Travel Rule messaging protocols for counterparty data exchange.