← Back to blog

AML for crypto funds: the UK compliance framework

July 26, 2026
AML for crypto funds: the UK compliance framework

What AML obligations apply to UK crypto funds?

Anti-money laundering compliance for crypto funds in the United Kingdom is governed by a layered framework that sits at the intersection of the Money Laundering Regulations (MLR 2017), the Financial Conduct Authority's supervisory regime, and FATF standards. Any fund managing, dealing in, or providing custody over crypto assets falls within scope as a cryptoasset business under the UK Money Laundering Regulations (UKMLR), and must register with the FCA before conducting regulated activity.

The core AML obligations are not optional additions to a fund's operating model. They are structural requirements that must be embedded across the entire compliance framework:

  • Customer due diligence (CDD): Verify the identity of investors, beneficial owners, and counterparties at onboarding and on a risk-sensitive ongoing basis.
  • Enhanced due diligence (EDD): Apply heightened scrutiny to high-risk investors, politically exposed persons (PEPs), and transactions from higher-risk jurisdictions.
  • Transaction monitoring: Maintain automated or manual systems to detect unusual patterns in crypto asset flows and flag potential suspicious activity.
  • Suspicious activity reporting (SAR): Submit SARs to the National Crime Agency (NCA) promptly when suspicion of money laundering or terrorist financing arises.
  • Sanctions screening: Screen investors and counterparties against UK financial sanctions lists maintained by the Office of Financial Sanctions Implementation (OFSI).
  • Travel Rule compliance: Transmit originator and beneficiary data for qualifying crypto transfers in line with FATF standards and UK implementation requirements.
  • KYC for cryptocurrency funds: Integrate investor eligibility checks into subscription and redemption workflows as a standing compliance control.
  • Staff training: Deliver ongoing, role-specific AML training tailored to virtual asset risk profiles.

The FCA's cryptoassets AML/CTF regime makes clear that compliance extends well beyond a checklist. Funds must demonstrate a documented, risk-based understanding of their exposure to financial crime, updated regularly as market conditions and regulatory expectations evolve. The era of treating AML as a back-office formality has closed; the FCA now expects board-level accountability and institutional-grade controls as a baseline.


How FCA registration and licensing apply to crypto funds

Infographic outlining UK crypto AML compliance steps

Regulatory mandate and licensable activities

Every UK crypto fund that falls within the UKMLR definition of a cryptoasset business must register with the FCA under Regulation 14A of the MLR 2017 before carrying on any regulated cryptoasset activity. Registration is not a light-touch process. The FCA assesses whether the applicant has adequate AML systems and controls, fit and proper management, and a credible compliance framework before granting approval.

Licensable activities for crypto funds typically include:

  • Portfolio management of crypto assets on behalf of investors
  • Arranging or executing transactions in crypto assets
  • Operating a crypto trading platform or exchange
  • Providing custody or safeguarding services for crypto assets
  • Issuing or administering crypto assets, including tokens
  • Providing financial promotions relating to crypto assets under the cryptoasset promotions regime

The FCA's cryptoasset financial promotions regime further restricts how funds may communicate with retail investors, adding a marketing compliance layer on top of AML obligations.

FCA supervisory expectation: "Cryptoasset businesses must have in place systems and controls to identify, assess, monitor and manage money laundering and terrorist financing risks. These must be proportionate to the nature, scale and complexity of the firm's activities." — FCA, Cryptoassets AML/CTF Regime

Registration process and ongoing supervision

The registration process requires funds to submit detailed documentation covering their business model, ownership structure, AML policies and procedures, risk appetite, and the credentials of key personnel. The FCA conducts a substantive review and may request additional information or impose conditions on registration.

Once registered, funds remain subject to ongoing FCA supervision, which includes:

  • Periodic supervisory visits and desk-based reviews
  • Requests for management information and compliance data
  • Thematic reviews targeting specific AML risk areas
  • Enforcement action where material deficiencies are identified

Funds seeking to understand the full scope of FCA licensing requirements should map their activities carefully against the UKMLR definitions before applying, since misclassification of activities is a common cause of registration delays and rejections.


Capital adequacy, prudential standards, and governance for AML

Capital and prudential requirements

Crypto funds operating in the UK must maintain capital buffers sufficient to cover their compliance risk exposures, not merely their market and credit risks. Prudential modelling must account for the heightened volatility of crypto assets, the cost of maintaining AML infrastructure, and the potential financial impact of regulatory action. The FCA expects funds to demonstrate that their capital position remains adequate under stress scenarios that include compliance failures.

Key prudential expectations include:

  • Minimum capital thresholds calibrated to the fund's activity type and risk profile
  • Liquidity buffers to cover operational disruptions, including those arising from AML-related account restrictions
  • Stress testing that incorporates regulatory and reputational risk scenarios specific to crypto markets
  • Capital planning that reflects the cost of technology investment in AML systems and ongoing compliance staffing

Governance and control requirements

Effective AML compliance in crypto funds requires board-level governance with clearly assigned responsibilities, capital adequacy to cover risks, and compliance officers empowered to enforce controls. The board carries ultimate accountability for the fund's AML framework and must demonstrate active engagement with compliance risk, not merely formal sign-off on policies.

Governance structures must include:

  • A designated Money Laundering Reporting Officer (MLRO): A senior individual with sufficient authority, resources, and independence to discharge their statutory obligations under the Proceeds of Crime Act 2002 (POCA) and the Terrorism Act 2000.
  • Board-level AML oversight: Regular reporting from the MLRO to the board, with documented board consideration of AML risk appetite and control effectiveness.
  • Internal audit function: Independent periodic review of the AML framework, with findings reported directly to the board or audit committee.
  • Segregation of client assets: Strict operational separation of investor funds from the fund's own assets, with documented controls over transfers and reconciliations.
  • Risk management framework: A documented, risk-based approach to identifying and mitigating AML exposures, reviewed at least annually.
  • Prudential modelling: Capital and liquidity models that incorporate compliance cost projections and regulatory risk scenarios.

The MLRO role in a crypto fund carries particular weight. Given the pseudonymous nature of blockchain transactions and the speed at which crypto assets can move across borders, the MLRO must have both the technical understanding to interpret blockchain analytics outputs and the regulatory authority to escalate concerns without obstruction.


Legal advisor reviewing crypto fund governance report

AML/CFT compliance and the Travel Rule for crypto funds

Customer due diligence and enhanced due diligence

CDD requirements for crypto funds go beyond standard identity verification. Funds must understand the source of funds and source of wealth for each investor, assess the risk profile of the investor's jurisdiction, and apply ongoing monitoring proportionate to that risk. For institutional investors, this means verifying the ultimate beneficial ownership chain and assessing the AML controls of the investing entity itself.

EDD is mandatory for:

  • PEPs and their associates
  • Investors from jurisdictions on the FATF grey or black lists
  • High-value or complex transactions with no apparent economic rationale
  • Investors whose source of wealth includes proceeds from crypto mining, token sales, or DeFi activity with limited audit trails

Ongoing CDD requires funds to refresh investor profiles when material changes occur, such as a change in beneficial ownership, a significant increase in investment volume, or a transaction pattern inconsistent with the investor's stated risk profile.

Transaction monitoring

Automated transaction monitoring is the operational backbone of AML compliance for crypto funds. Systems must be calibrated to detect:

  • Structuring patterns designed to avoid reporting thresholds
  • Rapid movement of assets through multiple wallets or exchanges
  • Transactions involving addresses flagged by blockchain analytics tools
  • Unusual redemption requests, particularly those involving conversion to privacy coins or self-hosted wallets

Regular compliance training and surveillance, as the FCA's AML/CTF regime makes clear, enhance detection quality and improve the accuracy of SAR submissions to the NCA.

The FATF Travel Rule

The FATF Travel Rule requires crypto funds and virtual asset service providers (VASPs) to collect, verify, and transmit originator and beneficiary information for crypto transfers above designated thresholds. In the UK, this obligation is implemented through the MLR 2017 amendments and aligns with FATF Recommendation 16.

Travel Rule compliance requirement: Crypto funds must obtain and transmit the name, account number, and address of both the originator and beneficiary for qualifying transfers, and must not execute transfers where required information cannot be obtained or verified.

Practical Travel Rule compliance for crypto funds involves:

  • VASP counterparty due diligence: Verify that receiving VASPs are registered or licensed in their home jurisdiction before transmitting funds.
  • Data transmission protocols: Implement technical solutions (such as TRISA, OpenVASP, or Sygna Bridge) to exchange Travel Rule data with counterparty VASPs.
  • Self-hosted wallet policies: Apply enhanced scrutiny to transfers involving unhosted wallets, including blockchain analytics assessment and, where risk warrants it, source of funds documentation.
  • Threshold monitoring: Maintain systems to aggregate transfers and apply Travel Rule obligations where cumulative thresholds are met.
  • Record retention: Retain Travel Rule data for a minimum of five years in line with UKMLR requirements.

The Travel Rule creates a direct link between KYC for cryptocurrency funds and transaction execution. A fund that cannot obtain compliant Travel Rule data from a counterparty VASP must decline the transaction, not merely flag it for review.


Technology, custody controls, and risk management in practice

Workspace with blockchain analytics tools and documents

Custody governance

Custody in crypto funds is primarily a compliance and governance challenge rather than a purely technical one. Regulators scrutinise key control arrangements, transfer approval processes, and asset segregation more closely than the underlying infrastructure. Funds failing to use qualified custodians where required risk regulatory audit failures on "know your asset" and safeguarding grounds.

Custody governance requirements include:

  • Qualified custodian arrangements: Where required by the fund's structure or investor base, assets must be held by a custodian that meets FCA standards for safeguarding.
  • Key control segregation: Private key management must be subject to multi-party authorisation, with documented approval workflows for all transfers.
  • Asset segregation: Investor assets must be held separately from the fund manager's own assets, with daily reconciliation and independent verification.
  • Transfer approval controls: All outbound transfers must be subject to a documented approval process, including AML screening of destination addresses before execution.
  • Custody audit trail: Maintain a complete, immutable record of all custody events, including key generation, transfers, and access logs.

Blockchain analytics and forensic tools

Blockchain analytics tools are now a standard expectation for crypto fund AML programmes. Tools such as Chainalysis, Elliptic, and TRM Labs provide risk scoring for wallet addresses and transactions, enabling funds to identify exposure to illicit activity before executing transfers. The FCA expects funds to use these tools as part of a proportionate, risk-based monitoring framework, not as a substitute for human judgement.

Effective use of blockchain analytics involves:

  • Pre-transaction screening: Score destination and source addresses before executing any transfer.
  • Ongoing portfolio monitoring: Periodically re-screen wallet addresses associated with the fund's holdings for changes in risk profile.
  • Alert triage: Establish documented procedures for reviewing and escalating analytics alerts, with clear ownership and response timescales.
  • Sanctions screening integration: Cross-reference analytics outputs with OFSI and UN sanctions lists in real time.

For funds exploring AML integration in DeFi contexts, the challenge is compounded by the absence of centralised counterparties, making blockchain analytics the primary source of risk intelligence.

Pro Tip: Configure your blockchain analytics platform to generate automatic alerts for any transaction involving a wallet address with a risk score above your documented threshold, and ensure the alert triage process is logged for regulatory audit purposes.

Risk management framework

A crypto fund's risk management framework must integrate AML controls with operational and market risk processes. This means:

  • Maintaining a documented AML risk assessment, updated at least annually and following any material change in the fund's activities or investor base
  • Incorporating AML risk into the fund's overall risk register, with board-level visibility
  • Establishing escalation pathways that connect the MLRO, risk function, and board without delay
  • Reviewing the effectiveness of controls through periodic testing, not merely through policy documentation

Enforcement exposure, penalties, and practical compliance durability

The FCA's enforcement posture towards crypto AML failures has hardened considerably. Recent enforcement actions have imposed record fines on crypto entities for AML compliance failures, including poor KYC checks and weak transaction monitoring. The FCA has also used its powers to cancel registrations, impose restrictions on business activities, and pursue individuals as well as firms.

The consequences of non-compliance extend beyond financial penalties:

  • Registration cancellation: Loss of FCA registration terminates the fund's ability to operate in the UK.
  • Reputational damage: Public enforcement notices are published on the FCA register and widely reported, with lasting impact on investor confidence.
  • Criminal liability: Senior individuals, including MLROs and directors, may face personal criminal prosecution under POCA 2002 or the Terrorism Act 2000 for wilful or negligent AML failures.
  • Civil liability: Investors who suffer loss as a result of AML failures may pursue civil claims against the fund and its officers.

Practical compliance strategies

Maintaining compliance durability requires more than adequate policies. The FCA expects funds to demonstrate that controls are operating effectively in practice, not merely documented in a manual. Key strategies include:

  • Documentation discipline: Maintain complete, contemporaneous records of all CDD decisions, SAR submissions, and Travel Rule data exchanges. Gaps in documentation are treated as gaps in compliance.
  • Audit readiness: Conduct regular internal audits of AML controls, with findings tracked to resolution and reported to the board.
  • Staff training programmes: Deliver role-specific AML training at induction and at least annually thereafter, with records of completion retained. The FCA's AML/CTF regime explicitly requires training tailored to virtual asset risk profiles.
  • Regulatory horizon scanning: Monitor FCA guidance updates, FATF mutual evaluation reports, and legislative changes that affect the fund's AML obligations.
  • Third-party due diligence: Apply AML scrutiny to service providers, including custodians, exchanges, and technology vendors, as part of the fund's supply chain risk management.
  • Incident response planning: Establish a documented process for responding to AML incidents, including SAR submission, regulatory notification, and internal escalation.

For a broader view of crypto compliance obligations in 2026, including how enforcement trends are shaping programme design, the FCA's published guidance and thematic reviews remain the authoritative reference.


Embedding AML into valuation, investor workflows, and fund governance

Strategic integration of AML with valuation policies

AML controls that operate in isolation from a fund's valuation and operational workflows create audit gaps that regulators identify quickly; see the Guía de investigación de fondos cripto - Recovera for detailed external legal considerations on integrating AML controls with investor onboarding in crypto sector. Integrating AML into crypto fund valuation workflows requires clear documented rules on pricing sources, fair-value adjustments, and handling illiquid or fragmented market data consistently. Valuation methodology affects subscriptions, redemptions, fee calculations, and investor fairness; lapses raise governance issues that extend beyond AML into fiduciary duty.

Valuation policies must incorporate explicit hierarchy rules to price crypto assets consistently across fragmented and illiquid venues, preventing NAV volatility that triggers regulatory and investor concern. Where an asset cannot be priced reliably, the fund's AML framework must address the risk that illiquid or opaque assets may be used to obscure the movement of illicit value.

Key integration points include:

  • Pricing source governance: Document the hierarchy of pricing sources (primary exchange, aggregator, fair-value model) and the conditions under which each applies.
  • AML review at subscription: Verify investor CDD status before processing any subscription, and block subscriptions where CDD is incomplete or EDD is outstanding.
  • AML review at redemption: Screen redemption requests against sanctions lists and assess whether the redemption pattern is consistent with the investor's profile before releasing funds.
  • Fee calculation integrity: Ensure that NAV calculations used for fee purposes are not distorted by assets with unresolved AML flags.

Investor eligibility and KYC in subscription workflows

KYC for cryptocurrency funds must be embedded in the subscription process as a gate, not an afterthought. Investor eligibility checks should cover:

  • Identity verification and beneficial ownership confirmation
  • Source of funds and source of wealth documentation
  • Sanctions and PEP screening
  • Jurisdiction risk assessment
  • Investor classification (professional, high-net-worth, retail) with corresponding AML risk weighting

Redemption workflows require equivalent scrutiny. A redemption request that cannot be matched to a verified, screened investor account should not be processed until the discrepancy is resolved and documented.

Custody governance as a compliance control

Mature crypto funds embed AML controls within operational and strategic workflows for more effective risk management. Custody governance is a prime example: treating the custodian relationship as a compliance control, not merely a technical service, means subjecting the custodian to periodic AML due diligence, reviewing their own regulatory status, and ensuring that custody arrangements do not create gaps in the fund's "know your asset" obligations.

  • Custodian AML assessment: Review the custodian's own AML programme and regulatory status at onboarding and annually.
  • Asset provenance tracking: Maintain records of the origin of each asset held in custody, including the wallet address from which it was received and the blockchain analytics risk score at the time of receipt.
  • Transfer pre-approval: Require MLRO or deputy sign-off on any transfer above a documented threshold, with blockchain analytics screening completed before approval.
  • Incident escalation: Establish a direct escalation pathway from the custodian to the fund's MLRO for any custody event that raises AML concerns.

Pro Tip: Treat your annual custodian review as a regulatory audit rehearsal: request the custodian's most recent AML audit report, review their SAR submission statistics, and document your assessment of their compliance posture in your own risk register.

Funds operating across multiple jurisdictions should also consider how multi-jurisdiction AML obligations interact with their UK FCA registration, particularly where assets are held in custody outside the UK or where investors are domiciled in jurisdictions with differing AML standards.

The distinction between funds that treat AML as a central governance function and those that treat it as a back-office task is increasingly visible to the FCA. Integrating AML controls into valuation, custody, and investor eligibility workflows transforms compliance from a documentation exercise into a genuine risk management function, and that distinction is precisely what supervisors are looking for during thematic reviews and enforcement investigations.


How Cryptoverselawyers supports UK crypto fund AML compliance

Crypto funds navigating the FCA's AML requirements face a compliance burden that spans regulatory law, operational design, technology selection, and board governance. Cryptoverselawyers provides specialist legal and regulatory advisory services built specifically for this environment.

Cryptoverselawyers

Cryptoverselawyers advises crypto funds on the full scope of UK AML obligations: from FCA registration strategy and MLRO appointment through to Travel Rule implementation, blockchain analytics integration, and custody governance frameworks. The firm's lawyers combine deep regulatory knowledge with direct experience of virtual asset operations, which means advice is grounded in how funds actually work, not just how regulations read on paper. For funds with cross-border investor bases or multi-jurisdiction custody arrangements, Cryptoverselawyers draws on its experience across digital asset regulatory frameworks in over 30 jurisdictions to ensure that UK AML controls are calibrated against the full picture of the fund's risk exposure.

Whether you are preparing an initial FCA registration, responding to a supervisory review, or redesigning your AML framework following a material change in the fund's activities, Cryptoverselawyers delivers regulator-ready legal solutions. Contact the team directly to discuss your fund's compliance position and agree a structured engagement.