A practical playbook for VASPs and crypto businesses building a defensible AML transaction monitoring program.
On-chain meets off-chain — One risk picture, built from blockchain analytics and traditional transaction monitoring together.
Enforcement is no longer about whether a firm has a monitoring program. Two of the largest crypto AML penalties on record landed on firms with documented programs — the weaknesses only showed up in how those programs actually operated.
The rulebook keeps moving, too. MiCA's transitional window closed in July 2026, the EU's AML Regulation applies directly from July 2027, the US GENIUS Act brings stablecoin issuers inside the Bank Secrecy Act, and the UK's broader cryptoasset regime lands in October 2027. A program built for last year is already behind.
We built this guide to turn that shifting landscape into an operating model — grounded in what supervisors actually check, not just what a policy document says.
Inside you'll discover:
- How FATF, MiCA, the US BSA and GENIUS Act, and the UK, Hong Kong, Dubai, and Georgia's rules each turn the same three questions — know your customer, watch their activity, show the evidence — into enforceable requirements
- The four structural features that set crypto AML apart from fiat monitoring: irreversible settlement, pseudonymous addresses, borderless transfers, and transaction paths built to be followed across chains, mixers, and bridges
- Why on-chain visibility alone leaves a gap, and how risk assessment, KYC/KYB, screening, Travel Rule compliance, FIU reporting, and independent audit connect into one program
- How rule-based and machine-learning monitoring work together, the red-flag typologies specific to crypto — structuring, rapid layering, peel chains, dormant-wallet reactivation — and the alert-triage discipline that keeps a program workable
- What went wrong in the largest crypto AML enforcement actions on record and a supervisory-ready checklist to test your own program against
Most crypto AML programs don't fail on the page — they fail in production, in the gap between a documented control and one a supervisor can watch operate. Closing that gap is the difference between a monitoring tool and a monitoring program.
This guide is built for compliance officers and MLROs at VASPs, fintechs and neobanks adding crypto products, and exchanges, wallet providers, stablecoin issuers, and payment processors scoping a program to their actual risk.
Best for: compliance officers and MLROs at VASPs, fintechs and neobanks adding crypto products, and exchanges, custodial wallet providers, stablecoin issuers, and payment processors.




