Loading data...

AML (Anti-Money Laundering)

Security

Controls and monitoring that prevent illicit fund flows.

AML, or anti-money laundering, refers to laws, controls, and investigations designed to prevent criminals from disguising the source or destination of funds. In crypto, AML compliance can include customer due diligence, sanctions screening, blockchain transaction monitoring, recordkeeping, and reporting suspicious activity. Exact duties vary by jurisdiction, business model, customer type, and transaction risk.

Money laundering is often described in three broad stages: placing illicit value into the financial system, layering transactions to hide its trail, and integrating the value into apparently legitimate activity. Digital assets do not remove these risks. Public blockchains create durable transaction records that investigators can analyze, while privacy tools, chain hopping, mixers, stolen identities, and off-chain services may make attribution more difficult.

AML and KYC are related but not identical. Know Your Customer checks help a regulated business establish and verify who a customer is. AML is the wider program, which may include governance, risk assessments, staff training, transaction monitoring, sanctions controls, investigations, reporting, independent testing, and retention of records. A successful identity check does not make every later transaction low risk.

For example, an exchange may alert on rapid deposits and withdrawals involving recently stolen funds. A trained analyst reviews the blockchain path, customer profile, device information, stated purpose, and other evidence. The firm might request source-of-funds documents, restrict activity, reject a transaction, or file a report with the appropriate authority. A blockchain analytics score is an investigative signal, not a final legal conclusion.

AML matters to users because compliance reviews can affect deposits, withdrawals, onboarding, and account access. Keep transaction hashes, trade records, invoices, payroll documents, and evidence showing how funds were acquired. Respond only through official support channels. No legitimate compliance team needs a wallet seed phrase or private key, and scammers often impersonate investigators to steal assets.

Businesses should apply risk-based controls proportionate to their products and exposure. Rules should be documented, explainable, tested, and reviewed as laws and criminal methods change. Excessive data collection creates privacy and security risks, while weak monitoring exposes customers and the business to fraud and enforcement. Because requirements differ and evolve, companies should use qualified legal and compliance professionals in every jurisdiction where they operate.

Frequently asked questions

  • Obligations depend on the country and business model, but regulated exchanges, brokers, banks, custodians, and some payment or crypto service providers commonly fall within AML laws. They may need a risk-based program, customer checks, transaction monitoring, recordkeeping, sanctions screening, and suspicious activity reporting. Individuals should obtain legal advice before assuming a crypto activity is unregulated.
  • Crypto businesses combine customer information with blockchain analytics and conventional payment data. They may screen wallet addresses, trace sources and destinations, check sanctions and adverse information, assign risk scores, and investigate unusual patterns. Automated alerts support trained reviewers but do not prove wrongdoing. Good programs document decisions and avoid relying on one vendor score without context.
  • A provider may delay a transfer, restrict an account, or ask for information such as transaction hashes, wallet ownership, source of funds, and the purpose of activity. Provide accurate records through the provider's official channel and never share a seed phrase or private key. Filing a suspicious activity report is generally confidential and does not itself mean a customer committed a crime.