Crypto & VASP Compliance

AML compliance for crypto, built by practitioners.

The FCA actively supervises virtual asset firms, and rejects most registration applications it receives. KYCifi designs and documents the AML programme the FCA expects to see, enhanced by LÆdar AI, so what you submit reflects how you will actually operate.

MLR 2017FCA registrationTravel RuleFATF
crypto / aml-programmeReviewed
Business-wide risk assessmentTailored
CDD / EDDCalibrated
Transaction monitoringTriage defined
Travel Rule · unhosted walletsProcedure
FCA-ready programme, documented and defensible. Registration-ready
AML programmes for ExchangesCustodiansBrokers & OTCPayment processorsCrypto ATMs
The regulatory context

Who is caught by UK crypto AML rules?

Under the Money Laundering Regulations 2017 (as amended), any business offering cryptoasset exchange or custodian wallet services in the UK must register with the FCA as a cryptoasset business, and operating unregistered is a criminal offence. The scope is broader than many firms realise.

Exchanges & P2P platforms

Centralised exchanges and peer-to-peer trading platforms.

Custodian wallet providers

Firms holding private keys on behalf of customers.

OTC desks & brokers

Crypto over-the-counter desks and brokerage businesses.

Crypto ATM operators

Operators of cryptoasset cash machines.

Payment processors

Crypto payment processors facilitating merchant transactions.

NFT & DeFi (grey area)

Currently a grey area, but the UK has signalled wider scope; building now beats retrofitting under pressure.

AML/CFT obligations

What the FCA expects to see.

The FCA requires a complete, functioning AML framework, not a policy document assembled from templates. The common reason for rejection is not the business model; it is the compliance documentation.

Risk & governance

A business-wide risk assessment specific to your products and customers, an AML/CFT policy, an MLRO with real authority and board reporting, and an annual MLRO report.

Customer due diligence & EDD

CDD covering identity and beneficial ownership, a customer risk-rating framework calibrated to crypto risk, enhanced due diligence for higher-risk customers, and ongoing review.

Transaction monitoring

Documented monitoring rules and thresholds, an alert-triage process with escalation to the MLRO, SAR procedures and record-keeping, and blockchain analytics integration.

Travel Rule & training

FATF Travel Rule procedures above the £1,000 threshold, unhosted-wallet due diligence, sanctions screening, and a staff AML training programme with records.

Travel Rule

The Travel Rule: where most VASPs fall short.

The FATF Travel Rule requires originator and beneficiary information to travel with virtual asset transfers above the £1,000 threshold. Your firm must exchange customer data with the counterparty VASP on every qualifying transaction, and document what happens when the counterparty cannot or will not provide it.

Most firms understand they need a technical solution. Far fewer have documented the procedures around it, what happens at onboarding, how non-compliant counterparties are handled, and how transfers to unhosted wallets are treated. Those gaps are exactly what the FCA examines.

£1,000threshold above which originator and beneficiary data must travel with a transfer
Onboarding procedureRequired
Non-compliant counterpartiesRequired
Unhosted wallet handlingRequired
A technical solution aloneNot enough
In practice

The six gaps the FCA most commonly finds.

From our work supporting crypto businesses through FCA registration and supervisory review, these are the failures we see most often, and the ones that cause the most damage.

Generic risk assessment

A BWRA that reads like a template rather than the specific risks of the business. This is usually easy for a reviewer to spot.

No customer risk rating

Applying the same CDD to all customers. A privacy-coin trader and a small retail buyer are not the same risk profile.

Travel Rule procedures missing

A technical solution but no documented procedure, especially for unhosted wallets and non-compliant counterparties.

Monitoring without triage

Analytics tools that generate alerts, but no documented process for reviewing, closing or escalating them.

Untrained staff

Policies that exist on paper but have never been communicated to the people responsible for implementing them.

No MLRO governance

An MLRO in name only, with no annual report, no management information and no documented escalation decisions.

The practitioner advantage

Built by practitioners. Enhanced by technology.

KYCifi is, first, a specialist AML and KYC practice. Our crypto programmes are designed and documented by financial crime specialists who have taken firms through FCA registration and supervisory review, not generated from a template.

A template pack gives you

Documents

  • A generic BWRA, lightly tailored
  • Policies disconnected from how you operate
  • Gaps the FCA reliably finds
  • Evidence left for you to assemble
KYCifi gives you

A defensible programme

  • AML, KYC & virtual asset specialists
  • A framework built around your business model
  • Evidence the programme actually operates
  • Registration support and pre-submission review
KPMGDeloitteBank of New YorkMLR 2017FATF
The technology

LÆdar AI supports our specialists.

Our practitioners lead every engagement. LÆdar AI, our intelligence platform, does the legwork behind them, screening, monitoring and evidence, so judgement stays with the people and the programme is built as they work.

Sanctions & PEP screeningBlockchain analyticsTransaction monitoringDocumentationAudit-ready records
How KYCifi builds your AML programme

What you receive.

An end-to-end AML framework built from scratch around your business model, with all fees fixed and agreed in writing before work begins.

Business-Wide Risk Assessment

Tailored to your products, customers and jurisdiction.

AML/CFT Policy & procedures

A full suite of operating procedures, not a single document.

Customer Risk Rating framework

Calibrated to crypto-specific risk factors.

Transaction monitoring rule-set

Monitoring rules and a documented triage procedure.

FATF Travel Rule procedures

Including unhosted wallets and non-compliant counterparties.

FCA registration support

Application support and a pre-submission review.

Staff AML training

Training materials and delivery, with records.

Fixed, agreed fees

All fees fixed and agreed in writing before work begins.

We’ll tell you what your programme needs.

Book a free 15-minute consultation. We’ll assess your current compliance position and give you a clear action plan, and what it will cost to build it.

15 minutes. No cost. No commitment. Contact contact@kycifi.com