AML Program for Crypto Businesses

 

 

What an AML Program Must Contain

 

A compliant AML program for a crypto payment gateway is not a single document but a structured framework of policies, procedures, and controls. The Financial Action Task Force (FATF), FinCEN (US), and the EU's AML directives all require program components that address the same core areas, even if the specific requirements differ by jurisdiction:

        Written AML policy: A documented statement of the company's commitment to preventing money laundering and terrorist financing, approved by senior management and the board.

        Risk assessment: A formal, documented analysis of the company's inherent money laundering risks, considering customer types, geographies, products, and delivery channels. For a crypto payment gateway, this includes an assessment of each blockchain network supported and each merchant sector served.

        Customer due diligence (CDD) procedures: Written protocols for onboarding verification, UBO identification, source of funds, and ongoing monitoring.

        Transaction monitoring: Systems and procedures for detecting suspicious transaction patterns, with documented alert escalation workflows.

        Sanctions screening: Real-time screening processes and the specific lists screened, with documentation of match resolution procedures.

        SAR filing: Documented criteria for when to file a Suspicious Activity Report and the process for doing so.

        Recordkeeping: Procedures for retaining customer identification records, transaction records, and SAR-related documentation for the required retention period (5 years in most jurisdictions).

        Training: Annual AML training program for all relevant staff, with training records maintained.

        Independent audit: Regular review of AML program effectiveness by a party independent of the compliance function.

 

The AML Compliance Officer

 

Most regulatory frameworks require a designated AML Compliance Officer (AMLCO) — a senior individual with appropriate authority, resources, and independence to operate the AML program effectively. The AMLCO is personally accountable for program adequacy and is the primary point of contact with regulators on AML matters. In the US, the AMLCO is responsible for the BSA compliance program; in the EU under MiCA, the equivalent role is the compliance officer with CASP-level responsibility.

The AMLCO must have sufficient seniority to override business decisions when compliance requires — for example, refusing to onboard a profitable merchant whose risk profile is unacceptable, or suspending a merchant account pending investigation. Gateways that embed the compliance function within the sales or operations department, with no reporting line independent of revenue-generating management, have structurally compromised AML programs regardless of how well-written their policies are.

 

Risk-Based Approach — the Core Principle

 

AML regulation does not require identical controls for all customers and transactions — it requires controls proportionate to risk. A small, well-established e-commerce merchant in Germany processing €5,000 per month in stablecoin payments does not need the same intensity of monitoring as a high-volume merchant in a high-risk jurisdiction operating in a cash-intensive sector. The risk-based approach means allocating compliance resources where the actual money laundering risk is highest.

In practice, this means classifying merchants into risk tiers at onboarding based on business type, jurisdiction, transaction volume, product type, and ownership structure. Higher-risk tiers receive enhanced due diligence, more frequent transaction monitoring reviews, lower automatic approval thresholds, and more frequent relationship reviews. Lower-risk tiers receive streamlined processing. The risk tier assessment and the criteria that determine tier assignment must be documented and defensible to regulators.

 

AML Program vs. AML Policy — The Distinction

 

An AML policy is a high-level statement of intent and principles — typically one to five pages. An AML program is the full operational implementation: procedures, systems, controls, escalation paths, staff responsibilities, testing schedules, and records. Regulators examine programs, not policies. A gateway that has a well-worded AML policy but lacks documented transaction monitoring procedures, trained staff, and evidence of actual screening activity has an AML policy with no AML program behind it — a finding that attracts regulatory enforcement action.

 

 

Compliance Note: This glossary entry is provided for general educational purposes only and does not constitute financial, investment, legal, or tax advice. Industry terminology may vary across jurisdictions and providers; definitions herein may not directly reflect the specific features, terms, or specifications of Finassets' services. For details on Finassets' offerings, please refer to official product documentation or contact our team directly.