What KYC actually checks
Three things, in ascending order of how much trouble they cause.
Identity
A passport or national ID, matched against the name on the account. Automated systems compare the photograph to a live capture.
Address
A utility bill or bank statement, usually no older than three months. This one determines which country’s rules apply to the account.
Source of funds
Asked at higher volumes or when something looks unusual. This is the check people find intrusive, and it is also the one regulators care about most, because it is the point where laundering is supposed to be caught.
Who has to run KYC
Exchanges, custodial wallets, brokers and anyone converting between crypto and ordinary money. The obligation comes from anti-money-laundering law, and the international baseline is set by the FATF Travel Rule, which requires identifying information to travel alongside transfers above a threshold.
The cost of ignoring it is not theoretical. In 2025 the Canadian regulator FINTRAC fined the payment provider Cryptomus close to 177 million Canadian dollars for failures in this area, after which the service introduced mandatory verification for its users. That figure remains the clearest public illustration in this industry of what the requirement is worth.
Why a payment gateway does not ask your customers for KYC
This is where most confusion sits, so it is worth stating plainly.
A crypto payment gateway verifies the merchant, not the payer. The merchant goes through KYB, the business equivalent of KYC. The person paying for an order sends a transfer from their own wallet and is asked for nothing, in the same way a shop does not check identity documents from someone paying cash.
The reason is structural. The gateway has a business relationship with the merchant and none with the merchant’s customer. It screens the incoming transaction for risk, which is a different obligation, and it does that without needing anyone’s passport.
What this does not mean is that a gateway operates outside the rules. It means the procedure applies where the relationship exists.
What happens to the data
Worth knowing, because it is the part people worry about and rarely ask.
A verified company stores the documents for a retention period set by law, commonly five years after the relationship ends, and has to be able to produce them on request from a regulator. It cannot use them for anything else, and in most jurisdictions it cannot delete them early either, even if the customer asks.
Verification through a third-party provider is the norm rather than the exception. Companies like Sumsub, Jumio and Onfido run the checks and pass a result back, which means the documents often sit with a specialist rather than with the service the customer signed up to.