← Back to blog

US crypto AML requirements: the 2026 compliance guide for crypto firms

August 16, 2026
US crypto AML requirements: the 2026 compliance guide for crypto firms

Every US-based crypto firm that accepts and transmits value substituting for currency is a money services business (MSB) under the Bank Secrecy Act (BSA), must register with FinCEN within 180 days of commencing operations, and must maintain a written, risk-based anti-money laundering programme from day one. Those are the three non-negotiable starting points. Layered on top are Travel Rule data obligations triggered at $3,000, OFAC sanctions screening, and a rapidly expanding rulemaking agenda driven by the GENIUS Act and FinCEN's Notice of Proposed Rulemaking (NPRM) on unhosted wallets.

Immediate priority actions:

  • Register with FinCEN as an MSB if your business model involves exchanging, administering, or transmitting convertible virtual currency (CVC) or legal tender digital assets (LTDA).
  • Draft and adopt a written AML programme covering internal controls, a designated compliance officer, independent testing, and staff training before you process your first transaction.
  • Map your Travel Rule and OFAC data flows — identify every counterparty institution, assess whether your technology stack can pass originator and beneficiary data at the $3,000 threshold, and screen all wallet addresses against the OFAC Specially Designated Nationals (SDN) list.

Three steps to start complying today:

  1. Determine whether your business model triggers MSB status using FinCEN's 2013 and 2019 guidance (see Section 3 below).
  2. File your FinCEN MSB registration via the BSA E-Filing System and begin drafting your AML programme simultaneously.
  3. Commission a gap assessment covering Travel Rule readiness, KYC/CDD procedures, SAR filing protocols, and state money transmitter licence requirements in every state where you have customers.

US crypto AML requirements: the federal statutory framework

Three statutes form the foundation of AML obligations for crypto firms operating in the United States.

  • Bank Secrecy Act (BSA), 31 U.S.C. §§ 5311–5336: The primary AML statute. It authorises FinCEN to require financial institutions, including MSBs, to maintain records, file reports, and implement AML programmes. All implementing regulations sit in 31 CFR Chapter X.
  • GENIUS Act (Guiding and Establishing National Innovation for US Stablecoins Act, 2025): Enacted in 2025, this statute formally classifies payment stablecoin issuers (PPSIs) as financial institutions for BSA purposes, requiring them to maintain AML and sanctions programmes equivalent to those of other regulated financial institutions. It also directs FinCEN and OFAC to issue implementing rules, several of which are in active rulemaking as of 2026.
  • International Emergency Economic Powers Act (IEEPA) and Executive Orders: The statutory basis for OFAC's sanctions programmes, which apply to all US persons regardless of the asset class involved.

Federal agencies and their roles:

  • FinCEN (Financial Crimes Enforcement Network): Administers the BSA, maintains the MSB registration database, issues interpretive guidance, and refers cases for civil enforcement. FinCEN's 2019 CVC guidance and its 2020 NPRM on unhosted wallets are the two most operationally significant documents for crypto firms.
  • OFAC (Office of Foreign Assets Control): Administers US sanctions programmes. Crypto firms must screen wallet addresses, customers, and counterparties against OFAC's SDN list and comply with blocking and reporting obligations.
  • DOJ (Department of Justice): Pursues criminal enforcement of BSA violations, including wilful failure to register and failure to maintain an AML programme.
  • SEC and CFTC: Jurisdiction overlaps where a crypto asset is a security (SEC) or a commodity derivative (CFTC). AML obligations under the BSA apply independently of securities or commodities classification, but SEC-registered broker-dealers and CFTC-registered futures commission merchants have parallel AML programme requirements under their own regulators.

Key defined terms:

TermDefinition
MSBMoney services business — includes money transmitters, CVC exchangers and administrators
CVCConvertible virtual currency — a medium of exchange with no legal tender status that can be exchanged for real currency
LTDALegal tender digital asset — a digital representation of fiat currency
PPSIPayment stablecoin issuer — defined by the GENIUS Act as a financial institution for BSA purposes
VASPVirtual asset service provider — the FATF term; broadly equivalent to MSB in the US context

Which crypto business models fall inside BSA coverage?

FinCEN's 2013 interpretive guidance established the foundational taxonomy: a user of virtual currency who obtains it for personal use is not an MSB; an exchanger who accepts and transmits CVC in exchange for real currency, funds, or other CVC is a money transmitter; an administrator who issues CVC and has the authority to redeem or withdraw it from circulation is also a money transmitter. The 2019 CVC guidance extended this framework to a wider range of business models.

Business model coverage at a glance:

  • Centralised exchanges (CEX): Almost always MSBs. Accepting fiat or crypto and transmitting CVC to customers constitutes money transmission.
  • Custodial wallet providers: MSBs where the provider controls private keys and transmits value on behalf of customers.
  • OTC desks and P2P exchangers: MSBs if they accept and transmit value for customers, even informally.
  • Stablecoin issuers (PPSIs): Treated as financial institutions under the GENIUS Act; BSA and OFAC obligations apply regardless of whether the issuer also qualifies as a money transmitter under prior guidance.
  • Payment processors accepting crypto: MSBs where they accept crypto and settle in fiat or another crypto on behalf of merchants.
  • DeFi protocol operators: Fact-specific. A protocol that is genuinely decentralised with no controlling person may fall outside BSA coverage; a developer or operator who retains administrative control over funds or smart contract parameters is more likely to be treated as a money transmitter.
  • Miners and validators: Generally not MSBs when acting solely as validators; the analysis changes if they also operate a pool that accepts and distributes funds.
  • Software and hardware wallet providers (non-custodial): Generally not MSBs, as they do not control customer funds.

Self-assessment checklist:

  1. Does your business accept CVC or fiat from customers?
  2. Does it transmit that value to another person or address on their behalf?
  3. Does it issue a CVC or LTDA and retain the authority to redeem it?
  4. Does it exchange one form of value for another as a business?

A "yes" to any of these questions warrants immediate legal review. FinCEN's 2019 CVC guidance is explicit: nomenclature does not determine regulatory treatment. Calling your token a "utility token" or your service a "protocol" does not exempt it from BSA analysis if the underlying activity involves accepting and transmitting value that substitutes for currency.


Core AML programme duties under the BSA for crypto firms

The BSA requires every MSB to implement a written AML programme with four minimum elements. These are not aspirational standards — examiners treat their absence as a programme failure.

The four minimum elements:

  • Internal controls: Written policies and procedures covering customer identification, transaction monitoring, SAR filing, CTR filing, recordkeeping, and sanctions screening. For crypto firms, internal controls must address blockchain-specific typologies: chain-hopping, mixer use, high-velocity wallet activity, and unhosted wallet counterparties.
  • Independent testing: An annual (or more frequent) audit of the AML programme by a qualified party who is independent of the compliance function. This can be an internal audit team or an external firm, but the tester must have no operational responsibility for the programme being reviewed.
  • Designated AML compliance officer: A named individual with authority, resources, and board-level access to manage the programme. This person must be knowledgeable about BSA requirements and empowered to escalate issues without interference.
  • Ongoing training: All relevant staff — including customer-facing, operations, and technology teams — must receive AML training appropriate to their roles. Training records must be maintained.

CDD and KYC requirements:

FinCEN's Customer Due Diligence (CDD) rule requires MSBs to identify and verify the identity of customers, understand the nature and purpose of customer relationships, and conduct ongoing monitoring. For retail customers, this typically means collecting full legal name, date of birth, address, and a government-issued ID number. Enhanced Due Diligence (EDD) applies to higher-risk customers: politically exposed persons (PEPs), customers in high-risk jurisdictions, and those exhibiting unusual transaction patterns.

Reporting and recordkeeping thresholds:

  • Currency Transaction Reports (CTRs): Required for cash transactions exceeding $10,000 in a single business day. For crypto firms, this applies where fiat currency is involved; pure crypto-to-crypto transactions do not trigger CTR obligations under current rules.
  • Suspicious Activity Reports (SARs): Required when a firm knows, suspects, or has reason to suspect that a transaction involves funds from illegal activity, is designed to evade BSA reporting, or lacks a lawful purpose. The filing threshold is $2,000 for MSBs. SARs must be filed within 30 days of detection (60 days if no suspect is identified at the time of detection). The SAR and all supporting documentation must be retained for five years.
  • Recordkeeping: Transaction records, customer identification documents, and AML programme materials must be retained for five years and be retrievable within a reasonable time for examination.

Pro Tip: Maintain a dedicated, immutable audit log that captures every blockchain analytics query, alert disposition, and SAR decision alongside the off-chain KYC record. Examiners increasingly expect to see a complete, timestamped decision trail — not just the SAR itself, but the reasoning that led to it or the documented rationale for not filing.

For a broader view of how AML programme design applies across Web3 business models, the AML/CTF for Web3 compliance guide published by Cryptoverselawyers covers the programme architecture in detail.


Travel Rule requirements: what data to collect, retain, and pass along

The Travel Rule is one of the most operationally complex obligations for crypto firms, and it is also the area where FinCEN's rulemaking is most active in 2026.

Thresholds and data requirements:

Per FinCEN's Funds Travel Regulations Q&A, the Travel Rule applies to transmittals of funds equal to or greater than $3,000. At that threshold, the following data must travel with the transfer:

NPRM thresholds for unhosted wallets:

The 2020 FinCEN NPRM proposed additional obligations for transactions involving unhosted or covered wallets. Under the proposed rule, a crypto MSB would be required to:

  • Verify and record the identity of a customer whose transaction with an unhosted wallet counterparty exceeds $3,000 (recordkeeping trigger).
  • Report transactions where the aggregate value with an unhosted wallet counterparty exceeds $10,000 within a 24-hour period (reporting trigger).

These proposals remain subject to finalisation, but firms should treat them as the direction of regulatory travel and build data-capture capabilities accordingly.

Intermediary obligations:

FinCEN's guidance is clear on intermediary duties: an intermediary financial institution that receives Travel Rule data must pass it on to the next institution in the chain. Critically, an intermediary is not required to retrieve information that a preceding institution failed to provide, except in limited circumstances. This means the burden of accurate, complete data sits with the originating institution.

Implementation considerations:

  • Hosted-to-hosted transfers: Both institutions are regulated; Travel Rule data exchange is technically feasible using messaging protocols such as IVMS101.
  • Hosted-to-unhosted transfers: The originating institution must collect and retain counterparty data even where no receiving institution exists to receive it. This is the core challenge the NPRM addresses.
  • Aggregation: Transactions must be aggregated across a business day when they are part of a series of connected transfers to the same beneficiary.

Pro Tip: Implement a Travel Rule solution that integrates directly with your core transaction engine rather than as a bolt-on. Post-transaction data collection is both operationally fragile and regulatorily problematic — you cannot retroactively satisfy a Travel Rule obligation after the funds have moved.


State licensing: money transmitter triggers and notable differences

Federal MSB registration with FinCEN does not substitute for state money transmitter licences. Most states require a separate licence to transmit money, and crypto firms are subject to those requirements in every state where they have customers, not just where they are incorporated.

Common state licensing triggers and requirements:

  • Accepting money or monetary value from a customer and transmitting it to another person or location.
  • Holding customer funds, even temporarily, in the course of a payment or exchange.
  • Issuing stored value or payment instruments.

Typical licence conditions include a surety bond (amounts vary widely by state, from tens of thousands to several million dollars), minimum net worth requirements, consumer protection disclosures, and annual reporting obligations.

States with particularly demanding regimes:

  • New York: The BitLicense regime, administered by the New York Department of Financial Services (NYDFS), requires a separate virtual currency business licence in addition to a standard money transmitter licence. It imposes capital requirements, cybersecurity standards, and AML programme requirements that go beyond federal minimums.
  • California: The Department of Financial Protection and Innovation (DFPI) administers the Digital Financial Assets Law (DFAL), which came into force in 2025 and requires a licence for digital financial asset business activity.
  • Texas, Florida, and Illinois: Active money transmitter regimes with crypto-specific guidance; each requires separate applications and maintains its own examination schedule.

State licensing timeline and sequencing:

  1. Weeks 1–4: Identify all states where you have or expect to have customers. Map each state's money transmitter statute to your business model.
  2. Weeks 4–8: Prioritise applications in states with the largest customer bases and the most demanding regimes (New York, California). Prepare surety bonds and financial statements.
  3. Weeks 8–24: File applications in remaining states. Many states participate in the Nationwide Multistate Licensing System (NMLS), which allows a single application portal, but each state still conducts its own review.
  4. Ongoing: Maintain separate compliance calendars for each state licence, including annual reports, licence renewals, and change-of-control notifications.

Interaction between state and federal enforcement:

State examiners and FinCEN do not coordinate their examination schedules, but findings from one can trigger scrutiny from the other. A state examination that identifies weak CDD or SAR quality will often be shared with FinCEN. Firms operating in multiple states should maintain a single, consolidated AML programme that meets the highest applicable standard rather than maintaining separate programmes per state.

For a cross-jurisdictional perspective on structuring a compliant multi-state or multi-jurisdiction operation, the multi-jurisdiction crypto regulation guide from Cryptoverselawyers is a useful reference.


State licensing: money transmitter triggers and notable differences — overview diagram

OFAC sanctions obligations for crypto firms

OFAC's sanctions programmes apply to all US persons and US-nexus transactions, regardless of the asset class. For crypto firms, this means every wallet address, customer, and counterparty institution must be screened against the SDN list before a transaction is processed.

Core blocking and screening obligations:

  • SDN screening: Screen all customers, beneficial owners, wallet addresses, and counterparty institutions against the OFAC SDN list and any applicable country-based sanctions programmes (e.g., Iran, North Korea, Russia).
  • Blocking: If a transaction involves property of a blocked person or entity, the firm must block the transaction, freeze the assets, and file a report with OFAC within 10 business days.
  • IP and geolocation controls: Firms must implement controls to detect and block access from sanctioned jurisdictions. IP geolocation is a minimum; more sophisticated controls include device fingerprinting and behavioural analysis.
  • Recordkeeping: Records of blocked transactions must be retained for five years.

The GENIUS Act reinforces these obligations for PPSIs: stablecoin issuers are explicitly required to maintain sanctions compliance programmes equivalent to those of other BSA-covered financial institutions, including real-time SDN screening at the point of issuance and redemption.

Operational coordination between AML and sanctions teams:

Sanctions and AML are legally distinct obligations but operationally intertwined. A SAR filed for a transaction that also involves a blocked person must be coordinated with the OFAC blocking report — the two filings address different regulators but must be consistent. Firms should establish a single escalation protocol that routes potential sanctions hits to both the AML officer and the sanctions compliance officer simultaneously.

A recent enforcement pattern worth noting: OFAC has pursued civil penalties against crypto exchanges that failed to implement geolocation controls, allowing users in sanctioned jurisdictions to access their platforms. The penalty calculations in those cases were based on the total value of transactions processed, not the number of violations — a structure that produces very large numbers quickly for active exchanges.

For firms managing digital asset forensics in connection with sanctions investigations or incident response, Recovera Forensics provides specialist digital asset recovery and evidence collection services that can support both internal investigations and regulatory submissions.


Operational controls: KYC, transaction monitoring, and independent testing

Legal requirements only become compliance if they are embedded in operational controls that actually run. The gap between a written AML programme and an effective one is almost always an operational gap, not a policy gap.

KYC/CDD by customer type:

  • Retail customers: Full legal name, date of birth, residential address, government-issued ID number, and source of funds for higher-risk onboarding. Liveness checks and document verification via automated identity verification tools are standard practice.
  • Institutional counterparties: Entity name, jurisdiction of incorporation, beneficial ownership (25% threshold), authorised signatories, and business purpose. For exchanges and OTC desks, this includes correspondent due diligence on the counterparty's own AML programme.
  • Programme counterparties (e.g., stablecoin distribution partners): Full CDD plus a review of the counterparty's AML programme, licence status, and sanctions screening procedures.

Transaction monitoring design:

Effective transaction monitoring for crypto requires a combination of rule-based alerts and blockchain analytics. Rule-based alerts catch volume anomalies, rapid fund movement, and structuring patterns. Blockchain analytics tools trace the provenance of funds across the chain, identifying exposure to mixers, darknet markets, sanctioned addresses, and high-risk exchanges. Alert management requires a documented disposition process: every alert must be reviewed, and the disposition (cleared or escalated to SAR) must be recorded with a rationale.

Tablet and phone on modern office desk

Independent testing:

Independent testing must assess whether the AML programme is functioning as designed, not merely whether the policies exist. The scope should cover: customer onboarding procedures, transaction monitoring rule coverage and tuning, SAR quality and timeliness, Travel Rule data completeness, and training records. Findings must be reported to senior management and the board, with remediation tracked to closure.

Pro Tip: Align your fraud, AML, and IT security teams on a shared alert triage protocol. Fraud typologies in crypto — account takeover, social engineering, and synthetic identity — frequently overlap with money laundering typologies. A shared alert queue with defined escalation paths reduces duplicate work and ensures that a fraud alert that also has AML implications reaches the compliance officer before the transaction is reversed.

The AML tips for crypto firms guide from Cryptoverselawyers covers practical monitoring design and audit preparation in further detail.


Technology, custody, and Travel Rule implementation

Custody architecture is not just a product decision — it determines which AML obligations apply and how difficult they are to satisfy.

Wallet and custody taxonomy:

Custody modelWho controls private keysTravel Rule obligationKey compliance controls
Hosted custodial walletThe firmFull Travel Rule appliesIVMS101 data exchange with counterparty institutions
Custody-as-a-serviceThird-party custodianDepends on contractual arrangementDue diligence on custodian's AML programme
Self-custody / non-custodialThe customerNo Travel Rule obligation on the firm for that walletUnhosted wallet NPRM recordkeeping at $3,000
Unhosted wallet counterpartyThird party unknownNPRM recordkeeping and reporting obligationsIdentity verification and address screening

Travel Rule implementation architecture:

Passing Travel Rule data on crypto rails requires a messaging layer that sits alongside the blockchain transaction. The IVMS101 data standard, developed by the Joint Working Group on interVASP Messaging Standards, is the most widely adopted format. Firms should select a Travel Rule solution that supports IVMS101, integrates with their core transaction engine via API, and maintains an immutable log of every data exchange for examination purposes.

Blockchain analytics integration:

Chain analytics tools should be integrated at three points: pre-transaction (screening the destination address before funds move), post-transaction (monitoring for unexpected routing or exposure), and periodic (re-screening existing customer wallets as new intelligence becomes available). The output of every screening query should be logged with a timestamp and disposition.

Architecture note: Build your Travel Rule data store as a separate, append-only database. Regulators expect to see a complete, unaltered record of every Travel Rule data exchange. A mutable database that allows records to be edited after the fact creates both an examination risk and a potential obstruction issue.


The pattern in BSA enforcement against crypto firms over the past several years is consistent: large civil money penalties for weak KYC, inadequate transaction monitoring, failure to file SARs, and, in the most serious cases, failure to register as an MSB at all. Criminal referrals have followed in cases where senior management was aware of the deficiencies and failed to act.

Common examination findings:

  • CDD files that are incomplete or not updated after initial onboarding.
  • Transaction monitoring rules that have not been tuned since implementation, producing either excessive false positives (alert fatigue) or systematic blind spots.
  • SARs that are filed late, filed with insufficient narrative detail, or not filed at all for transactions that clearly warranted them.
  • Travel Rule data that is collected but not transmitted to counterparty institutions, or transmitted in a format the counterparty cannot process.
  • No documented independent testing, or testing conducted by the compliance team itself.

Immediate remediation steps when a gap is found:

  1. Contain: Suspend the affected process or product feature until the gap is remediated. Document the decision and the rationale.
  2. Root cause: Conduct a structured root cause analysis. Determine whether the gap is a policy failure, a technology failure, a training failure, or a resourcing failure.
  3. Report internally: Brief the board and senior management within 48 hours of identifying a material gap. Document the briefing.
  4. Assess voluntary disclosure: Evaluate whether the gap warrants voluntary self-disclosure to FinCEN or OFAC. Voluntary disclosure is a significant mitigating factor in civil penalty calculations.
  5. Remediate and document: Implement the fix, test it, and document the entire remediation process. Examiners will ask for this documentation.

Enforcement actions consistently cite governance failures alongside technical compliance failures. Regulators expect the board to receive regular AML programme reports, to approve the annual independent testing plan, and to be briefed on material SAR filings and examination findings. A firm that can demonstrate active board engagement with its AML programme is materially better positioned in an enforcement context.


Practical 90–180 day compliance timeline for US crypto firms

Priority compliance checklist:

  1. Days 1–14: Conduct a legal analysis of your business model against FinCEN's 2013 and 2019 CVC guidance to confirm MSB status. Engage outside counsel if the analysis is not straightforward.
  2. Days 1–30: File FinCEN MSB registration via the BSA E-Filing System. The 180-day registration window runs from the date you commence money transmission activity — not from the date you incorporate.
  3. Days 15–45: Draft and adopt a written AML programme. Appoint a designated AML compliance officer with board-level reporting authority.
  4. Days 30–60: Procure and implement KYC/identity verification tooling. Establish CDD procedures for retail and institutional customers.
  5. Days 45–75: Implement transaction monitoring rules and integrate a blockchain analytics provider. Document the rule set and the rationale for each rule.
  6. Days 60–90: Conduct a Travel Rule gap assessment. Select a Travel Rule messaging solution and begin integration testing.
  7. Days 75–120: File state money transmitter licence applications in priority states (New York, California, and any state with a significant customer base).
  8. Days 90–120: Conduct initial staff AML training. Document attendance and assessment results.
  9. Days 120–150: Commission independent testing of the AML programme. Ensure the tester has access to transaction data, KYC files, SAR records, and monitoring alert logs.
  10. Days 150–180: Remediate findings from independent testing. Brief the board on programme status, testing results, and state licence progress.

Key performance indicators for board reporting:

  • SAR filing rate and average time from detection to filing.
  • Transaction monitoring alert volume, false positive rate, and average disposition time.
  • CDD completion rate at onboarding and periodic review.
  • Travel Rule data completeness rate (percentage of qualifying transmittals with full originator/beneficiary data).
  • State licence application status by jurisdiction.

Risk-based prioritisation for resource-constrained teams:

If your team is small, sequence your effort by regulatory risk, not by ease of implementation. FinCEN registration and a written AML programme come first because their absence is a criminal exposure. SAR filing and transaction monitoring come second because they are the most common examination findings. Travel Rule implementation and state licensing can follow, but should not be deferred beyond 90 days for firms with material transaction volumes.

WeekDeliverableOwner
1–2MSB legal analysis completeLegal / outside counsel
2–4FinCEN registration filedCompliance officer
3–6Written AML programme adoptedCompliance officer + board
4–8KYC tooling liveTechnology + compliance
6–10Transaction monitoring liveTechnology + compliance
8–12State licence applications filedLegal
10–14Travel Rule solution integratedTechnology
16–18Independent testing completeExternal auditor
20–24Remediation complete; board briefedCompliance officer

How Cryptoverselawyers approaches US crypto AML readiness

Cryptoverselawyers's typical engagement for a US-based crypto client begins with a structured AML readiness assessment: mapping the business model to BSA coverage, identifying registration obligations, and producing a gap analysis against the four BSA programme minimums and the Travel Rule. From there, the firm drafts the written AML programme, advises on KYC tooling selection, and supports state licence applications in parallel.

What distinguishes this approach is the combination of regulator-facing experience and cross-jurisdictional programme design. Many US crypto firms are also operating under MiCA in the EU, MAS in Singapore, or VARA in the UAE. Cryptoverselawyers designs AML programmes that satisfy US BSA requirements while remaining compatible with FATF standards and the specific requirements of other jurisdictions — avoiding the cost of rebuilding the programme from scratch for each regulator.

The firm's board briefing capability is a practical differentiator: compliance officers frequently need to translate complex regulatory developments (GENIUS Act implementation, FinCEN NPRMs) into board-level risk assessments. Cryptoverselawyers prepares those briefings as part of its standard engagement model.


Cryptoverselawyers: AML programme design and US compliance support

Navigating FinCEN registration, AML programme drafting, Travel Rule implementation, and multi-state licensing simultaneously is a significant operational undertaking — particularly for firms that are also managing product development and fundraising. Cryptoverselawyers provides a structured, end-to-end compliance engagement that covers every stage: MSB registration, written AML programme design, KYC and transaction monitoring framework, Travel Rule solution selection, and state licence strategy.

Cryptoverselawyers

The firm's US compliance practice is built around the practical reality that most crypto founders are not compliance professionals, and most compliance professionals are not crypto-native lawyers. Cryptoverselawyers bridges that gap with a team that understands both the technology and the regulatory framework. For firms with cross-border operations, the same team that designs your US BSA programme can align it with your VARA licensing obligations in Dubai or your MiCA requirements in the EU — one programme architecture, multiple jurisdictions.

To begin, request a pre-engagement compliance review. Cryptoverselawyers will assess your business model, identify your registration and programme obligations, and provide a prioritised remediation roadmap within two weeks. Contact the firm directly via Cryptoverselawyers to schedule your initial consultation.


Sources

Every compliance professional working in this space should maintain direct access to the primary regulatory documents. Secondary summaries — including this article — are useful for orientation, but examination-ready programmes are built on the primary text.

Primary sources:

How to use these sources in examinations:

When an examiner asks why your programme is designed a particular way, the answer should reference a specific FinCEN guidance document or Federal Register notice, not a secondary summary. Build your programme documentation with inline citations to primary sources.

Staying current:

Subscribe to FinCEN's email alerts at fincen.gov and OFAC's update notifications at ofac.treasury.gov. Monitor the Federal Register for new NPRMs and final rules — the GENIUS Act implementation rulemaking is ongoing, and material changes to PPSI and stablecoin obligations are expected throughout 2026. The AML for crypto funds compliance framework published by Cryptoverselawyers tracks key regulatory developments and is updated as significant guidance is issued.


This article provides general information about US AML regulatory requirements for crypto businesses and does not constitute legal advice. Regulatory obligations vary by business model, jurisdiction, and the specific facts of each situation. Consult a qualified legal professional and verify current requirements directly with FinCEN, OFAC, and relevant state regulators before making compliance decisions.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.