📋 Introduction: Why Compliance Matters
Crypto remittance businesses operate at the intersection of blockchain technology and financial regulation. As the industry matures, regulators worldwide are implementing comprehensive frameworks to ensure AML/CFT compliance, consumer protection, and financial stability.
Non-compliance can result in severe consequences: fines (ranging from $10,000 to millions), license revocation, criminal charges, and reputational damage. A proactive compliance approach is essential for sustainable business growth.
This checklist provides a comprehensive framework for crypto remittance businesses to achieve and maintain compliance across seven key areas:
- Registration & Licensing — Legal entity formation and regulatory registration
- AML/KYC Program — Customer due diligence and transaction monitoring
- Travel Rule Compliance — Information sharing for cross-border transfers
- Sanctions Compliance — OFAC, EU, and UN sanctions screening
- Data Privacy & Security — GDPR, CCPA, and cybersecurity requirements
- Tax Reporting — Income, VAT, and capital gains reporting
- Ongoing Monitoring — Regular audits, training, and policy updates
Compliance is not a one-time event — it's an ongoing process. Regulations evolve, and businesses must adapt. This checklist serves as a living document to guide your compliance journey.
🏛️ 1. Registration & Licensing
Before operating a crypto remittance business, you must establish a legal entity and obtain appropriate licenses. Requirements vary by jurisdiction but generally include:
Register your business as a corporation, LLC, or equivalent. Obtain a business license and tax identification number.
Register with FinCEN as a Money Services Business. File Form 107 and establish a BSA/AML program.
Obtain authorization under MiCA for crypto service providers. Submit application to your national competent authority.
Apply for a license under the Payment Services Act. Meet capital and operational requirements.
Obtain money transmitter licenses in each state where you operate. New York's BitLicense is one example.
Track license renewal dates. Maintain good standing with regulatory authorities.
☐ Legal entity registered
☐ Business license obtained
☐ FinCEN MSB registration (US)
☐ State money transmitter licenses (US)
☐ MiCA authorization (EU)
☐ PSA license (Singapore)
☐ Other jurisdiction licenses
☐ License renewal tracking system
🛡️ 2. AML/KYC Program
A robust AML/KYC program is the foundation of compliance. It must be risk-based and documented in writing.
Customer Due Diligence (CDD)
- Identity Verification — Collect and verify customer name, address, date of birth, and identification documents (passport, driver's license).
- Beneficial Ownership — For business customers, identify and verify ultimate beneficial owners (UBOs) owning 25% or more.
- Risk Assessment — Classify customers based on risk level (low, medium, high) based on jurisdiction, business type, and transaction patterns.
- PEP Screening — Screen customers against Politically Exposed Person (PEP) lists.
Transaction Monitoring
- Real-Time Monitoring — Monitor all transactions for suspicious patterns (large amounts, unusual frequency, rapid movements).
- Threshold Reporting — File Currency Transaction Reports (CTRs) for transactions above $10,000 (US).
- Suspicious Activity Reporting (SARs) — File SARs for suspicious transactions. Timely filing is critical.
- Record Keeping — Maintain transaction records for 5–7 years (varies by jurisdiction).
| Requirement | US (FinCEN) | EU (MiCA/5AMLD) | UK (FCA) | Singapore (MAS) |
|---|---|---|---|---|
| MSB Registration | Required | N/A (MiCA license) | N/A (FCA registration) | N/A (PSA license) |
| KYC/CDD | Required | Required | Required | Required |
| Travel Rule | $3,000 | €1,000 | £1,000 | SGD 1,500 |
| SAR Filing | Required | Required | Required | Required |
| Record Keeping | 5 years | 5 years | 5 years | 5 years |
☐ Written AML/KYC policy
☐ CDD procedures implemented
☐ Identity verification system
☐ PEP screening process
☐ Transaction monitoring system
☐ SAR filing procedures
☐ Record keeping system
☐ Independent audit (annual)
☐ AML compliance officer appointed
✈️ 3. Travel Rule Compliance
FATF Recommendation 16 (the Travel Rule) requires financial institutions and crypto service providers to share originator and beneficiary information for cross-border transfers above a certain threshold.
Key Requirements
- Thresholds — Vary by jurisdiction (US: $3,000, EU: €1,000, UK: £1,000, Singapore: SGD 1,500).
- Information Required — Originator name, address, account number; Beneficiary name and account number.
- Transmission — Information must be transmitted with the transfer or within a reasonable time.
- Compliance — VASPs must have systems to collect, verify, and transmit Travel Rule data.
Several solutions help VASPs comply with the Travel Rule: TRP (Travel Rule Protocol), OpenVASP, and InterVASP Messaging Standard (IVMS). These enable secure data sharing between compliant platforms.
☐ Travel Rule policy documented
☐ Threshold limits defined
☐ Information collection procedures
☐ Data transmission systems
☐ Cross-border transfer screening
☐ Counterparty VASP verification
☐ Record keeping for Travel Rule data
🚫 4. Sanctions Compliance
Sanctions compliance is critical for cross-border payments. Non-compliance with OFAC, EU, or UN sanctions can result in severe penalties — fines can exceed $1 million per violation.
- OFAC Compliance (US) — Screen all transactions against the Specially Designated Nationals (SDN) list. Implement sanctions screening systems.
- EU Sanctions — Comply with EU sanctions regimes and asset freezes.
- UN Sanctions — Screen against UN sanctions lists.
- Country-Level Restrictions — Some countries (Iran, North Korea, Syria, Crimea) are subject to comprehensive sanctions.
- Real-Time Screening — Implement real-time name and address screening for all customers and transactions.
☐ Sanctions policy documented
☐ OFAC screening system
☐ EU sanctions screening
☐ UN sanctions screening
☐ Real-time transaction screening
☐ Blocked property reporting procedures
☐ Sanctions training for staff
☐ Sanctions list updates (daily)
🔒 5. Data Privacy & Security
Crypto remittance businesses collect and process sensitive customer data. Compliance with data protection laws is non-negotiable.
- GDPR (EU/UK) — Ensure lawful basis for data processing. Provide rights to access, rectification, and deletion.
- CCPA/CPRA (California) — Provide opt-out rights and data access.
- Data Security — Implement encryption, access controls, and regular security audits.
- Data Breach Response — Develop and test a data breach response plan.
- Third-Party Vetting — Ensure compliance by data processors and third-party vendors.
☐ Privacy policy documented
☐ GDPR/CCPA compliance
☐ Data encryption (at rest and in transit)
☐ Access controls implemented
☐ Data breach response plan
☐ Third-party vendor assessments
☐ Privacy impact assessments
☐ Data subject request procedures
💰 6. Tax Reporting
Tax compliance varies by jurisdiction but generally includes income tax, VAT/GST, and capital gains reporting.
- Income Tax — Report revenue from fees and other income. Deduct allowable expenses.
- VAT/GST — Determine if crypto services are subject to VAT/GST in your jurisdiction. Register and remit as required.
- Capital Gains — Report capital gains on crypto held as assets.
- International Reporting — Report cross-border transactions and foreign accounts as required (FBAR, FATCA).
- Customer Tax Reporting — Provide tax documents (like 1099 forms in the US) to customers as required.
☐ Tax registration
☐ Income tax returns filed
☐ VAT/GST registered and filed
☐ Capital gains reporting
☐ FBAR/FATCA compliance (US)
☐ Customer tax documents issued
☐ Tax advisor engaged
☐ Tax records maintained (7 years)
🔄 7. Ongoing Monitoring & Continuous Improvement
Compliance is not static. Regulations evolve, risks change, and businesses grow. Ongoing monitoring is essential.
- Policy Reviews — Review and update AML/KYC policies annually or as regulations change.
- Staff Training — Provide regular compliance training for all employees.
- Independent Audits — Conduct annual independent compliance audits.
- Regulatory Updates — Monitor regulatory changes in all jurisdictions where you operate.
- Risk Assessments — Update risk assessments based on new products, markets, or threats.
- Technology Upgrades — Keep compliance systems updated with the latest technology.
☐ Annual policy review
☐ Staff training program
☐ Independent compliance audit
☐ Regulatory monitoring system
☐ Risk assessment updates
☐ Technology upgrades
☐ Incident response testing
☐ Compliance committee meetings