What an AML programme contains
A regulated company running one has five parts in place, and a regulator inspecting it will ask about each.
A written policy
describing how the company identifies and handles risk.
A responsible officer
, a named person accountable for compliance.
A risk assessment
covering the customer base, the products and the countries involved.
Ongoing monitoring
of transactions, with thresholds that trigger review.
Reporting and record-keeping
: suspicious activity reports to the relevant authority and retention of documentation, commonly for five years after the relationship ends.
Missing any one of these is a finding. Missing several is a fine.
How crypto changed the picture
Cash leaves no trail. A public blockchain leaves nothing but trail, and that inversion is the most consequential thing about AML in this sector.
Every transfer is recorded permanently and visible to anyone. Analytics firms cluster addresses into entities, label them, and trace funds across hops. A payment that touched a sanctioned address four transfers ago can be identified as such years later, which is not possible with banknotes.
The practical result is that compliance in crypto looks different from compliance in banking. Instead of asking every participant for a passport, a service screens the transaction itself against what the chain already shows.
What enforcement actually costs
Two figures give the scale.
In 2025 the Canadian regulator FINTRAC fined the payment provider Cryptomus close to 177 million Canadian dollars over failures in this area, after which the service introduced mandatory user verification.
Separately, custodial payment processors lost around 1,8 billion dollars to breaches between 2023 and 2025. Security and AML are distinct obligations, though regulators increasingly treat weakness in one as evidence about the other.
What a merchant is responsible for
Usually less than merchants expect.
Selling goods or services and accepting payment does not make a business a financial intermediary, and the AML obligations that bind exchanges and payment providers do not transfer to it. The gateway runs the programme; the merchant passes KYB and keeps its records.
What a merchant does carry is the obligation not to ignore what it can see. Accepting payment from a source you have been told is problematic is a different matter from not having checked.
Where the rules come from
Three layers, and they interact rather than stack neatly.
International
FATF issues recommendations, including the Travel Rule requiring identifying information to accompany transfers above a threshold between regulated intermediaries. FATF binds nobody directly; it binds countries that then bind companies.
Regional
The EU implements through MiCA and its anti-money-laundering directives, which set requirements for crypto service providers operating in or serving the bloc.
National
Each country’s financial intelligence unit interprets and enforces. This is the layer that issues fines, and the one that varies most.
A provider serving customers in several markets complies with all three, and the strictest requirement usually sets the practice everywhere.