Every AML control described elsewhere on this site applies to a virtual asset service provider. What changes is the operating envelope they have to run inside.
Two properties do most of the work. Settlement is final, so there is no recall to fall back on when a control fails. And users expect execution in seconds, so a check that takes too long does not survive contact with the product.
Why latency is a compliance concern, not a product one
A control that adds four seconds to a deposit gets reported as a conversion problem. The response is to loosen it, usually by widening the matching thresholds that produced the delay, and the loosening is rarely revisited once the complaint stops.
The control is then weaker than the policy says it is, and nobody decided that. Treating the time budget as a design constraint from the start is what prevents the slow erosion, and it is why an API-first deployment matters more here than in businesses where screening can sit in a separate console beside the workflow.
Continuous exposure needs continuous screening
| Traditional relationship | Virtual asset provider | |
|---|---|---|
| Activity | Periodic, often sparse | Continuous, frequently daily |
| Settlement | Reversible in most rails | Final on chain |
| Review cadence that fits | Periodic, event-driven | List-change driven |
| Counterparty | Usually a named party | Frequently an address |
A review calendar assumes exposure accumulates slowly enough for a scheduled look to catch it. When a customer transacts daily and settlement is final, the gap between reviews is the exposure.
Addresses are not people
Much of the counterparty risk here attaches to an address rather than a person. There are no identity attributes to match on, so the name, date of birth and jurisdiction comparison an analyst would use has nothing to work with.
That is a different assessment producing a different kind of answer, and it needs its own handling rather than being forced through a name-matching queue that was never designed for it. Self-hosted transfers are the sharpest version: ownership has to be established above the applicable threshold, and there has to be a stated position for the cases where it cannot be.
Evidence at volume
The reconstruction problem changes shape at scale. A supervisor asks about one transfer among millions, and the answer has to be retrievable, not merely recorded somewhere.
That makes evidence a retrieval design question as much as a logging one, which is easy to defer while volumes are small and expensive to retrofit once they are not.
For the sector view and whether the obligations apply to you, see the crypto industry page. For what must accompany a transfer and what to do when it arrives incomplete, see Travel Rule compliance. For the components, see identity verification, PEP and sanctions screening and transaction monitoring.
