← Back to blog

Crypto AML controls: what compliance teams must implement

August 5, 2026
Crypto AML controls: what compliance teams must implement

Crypto AML controls are a regulator-mapped, risk-based set of policies, people, processes and technology that make cryptoasset transactions traceable, screened and reportable to the standard the Financial Conduct Authority and the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs) require. If your firm handles cryptoassets in the UK, the FCA expects you to have these controls operational before you start offering in-scope services, not as a post-registration project. The EU's Transfer of Funds Regulation (TFR) and MiCA add cross-border obligations that UK firms with EU-facing activity cannot ignore.

Use this checklist to assess your current position against the minimum supervisory baseline:

  • FCA registration status: Confirm your firm is registered under the MLRs before conducting any in-scope cryptoasset activity.
  • ML/TF risk assessment: A documented, firm-specific risk assessment covering products, customers, geographies and delivery channels must exist and be reviewed at least annually.
  • CDD/KYC posture: Customer due diligence procedures must be applied at onboarding and on an ongoing basis; enhanced due diligence (EDD) triggers must be defined and evidenced.
  • Travel Rule readiness: A signed contract with a Travel Rule solution provider and evidence of integration must be in place; the threshold for originator/beneficiary data applies to transfers of crypto-assets involving self-hosted addresses under TFR.
  • Transaction monitoring: Automated monitoring rules must be live, tuned to your risk profile and generating alerts that are triaged within a defined SLA.
  • Sanctions screening: Real-time screening against UK, UN and OFAC consolidated lists must cover all customers, counterparties and wallet addresses at onboarding and on an ongoing basis.
  • MLRO appointment: A qualified Money Laundering Reporting Officer must be named, with a direct reporting line to the board and documented authority to file Suspicious Activity Reports (SARs).
  • SAR process: A documented internal reporting procedure must be in place, with clear escalation paths, a nominated officer and a record-keeping policy that retains SAR-related files for at least five years.

Table of Contents

Core AML controls every UK crypto firm must have in place

The following table maps each control category to its regulatory reference and the evidence supervisors expect to see. This is the inventory your compliance team should use to structure an internal gap analysis.

Control categoryRegulatory referenceEvidence supervisors expect
Governance and policiesMLRs; FCA supervisory guidanceBoard-approved AML/CTF policy; MLRO terms of reference; documented escalation matrix
ML/TF risk assessmentMLRs; FCA risk-based approachWritten, dated risk assessment; methodology document; annual review record
Customer due diligence (CDD)MLRs Reg. 28; MiCA Arts. 68–73Onboarding checklists; timestamped verification records; ongoing monitoring logs
Enhanced due diligence (EDD)MLRs; FCA guidanceEDD trigger criteria; case files with rationale; senior management approval records
Sanctions screeningUK Sanctions and Anti-Money Laundering Act 2018; OFSI guidanceScreening configuration records; hit/false-positive logs; escalation evidence
Transaction monitoring and blockchain analyticsMLRs Reg. 28; FCA supervisory focusRule inventory; alert triage logs; SLA compliance records; analytics integration evidence
Travel RuleTFR; FATF RecommendationSigned Travel Rule provider contract; integration test results; message logs
Self-hosted wallet attributionTFR; EBA guidanceWallet verification procedures; risk-scoring methodology; case-by-case decision logs
SAR processPOCA 2002; MLRsInternal reporting procedure; SAR register; NCA submission receipts
Record keepingMLRsFive-year retention schedule; data map; destruction logs
Training and awarenessMLRs Reg. 24Training records; completion rates; role-specific content evidence
Vendor and third-party managementMLRs; FCA outsourcing expectationsDue diligence files; contracts with data-access clauses; periodic review records
Independent testing and auditFCA supervisory expectationsAudit terms of reference; findings reports; management responses; remediation tracking

Self-hosted wallets deserve particular attention. The TFR and FATF guidance require firms to apply special measures when a transfer involves a self-hosted (non-custodial) address, including verifying that the address belongs to the customer and assessing the risk of the transfer. Many firms have a documented procedure for this but lack the technical capability to execute it consistently. Wallet attribution tools that combine on-chain clustering with identity-linked address databases are now a practical necessity, not a nice-to-have.

For transaction monitoring, the technical checklist should include:

  • Automated rule engine with configurable thresholds by product, customer segment and geography.
  • Blockchain analytics integration providing wallet risk scores, entity labels and cross-chain coverage.
  • Alert triage workflow with defined SLAs (typically 24–72 hours for high-severity alerts).
  • Escalation path from analyst to MLRO with documented handoff records.
  • Periodic rule review cadence (at minimum quarterly) with backtesting evidence.

Pro Tip: The most common supervisory failure Ai-thea observes is not the absence of a monitoring rule, but the absence of evidence that alerts were triaged and closed with a documented rationale. Supervisors do not just check that your system generates alerts; they pull a sample and ask to see the analyst's decision record. Build your case-management workflow to produce that record automatically, not retrospectively.

MiCA's KYC framework under Articles 68–73 makes KYC an ongoing obligation, not a one-time onboarding exercise. Record retention of at least five years and crypto-specific on-chain monitoring are explicit requirements. UK firms with EU-facing activity should align their CDD standards to MiCA even where they are not directly bound, because EU counterparties will apply those standards when assessing your firm.


How to build your implementation roadmap

Converting a control checklist into a delivered programme requires sequencing. Trying to implement everything simultaneously is the fastest route to a half-finished programme that satisfies no one. The phases below reflect the order in which dependencies typically resolve.

  1. Assess (Days 1–30). Conduct a gap analysis against the control table above. Map existing policies, systems and procedures to each control category. Identify critical gaps (missing MLRO, no sanctions screening, no Travel Rule provider) and document them with a risk rating. This phase produces the baseline that justifies your implementation priorities to the board.

  2. Design (Days 31–60). Draft or update your AML/CTF policy, risk assessment methodology and CDD procedures. Define your transaction monitoring rule inventory based on your product and customer risk profile. Appoint your MLRO if not already in post. This phase produces the governance documentation supervisors will request first.

  3. Procure (Days 61–90). Run vendor selection for blockchain analytics, Travel Rule and any KYC/identity verification tools you lack. Issue RFPs, evaluate responses and negotiate contracts. Regulators increasingly expect a signed Travel Rule provider contract to be in place at authorisation stage, so this phase cannot be deferred. Budget guidance: Travel Rule onboarding typically carries a medium implementation cost; blockchain analytics platforms range from lower-cost entry-level tools to enterprise pricing depending on transaction volumes and chain coverage.

  4. Integrate (Days 91–150). Connect analytics and screening tools to your transaction processing systems and case-management platform. Configure data flows, test API connections and validate that alert records are being logged correctly. This phase is where change management effort concentrates: analysts need training on new workflows before go-live, not after.

  5. Test (Days 151–180). Run backtests on your monitoring rules using historical transaction data. Conduct a red-team exercise to validate that your SAR escalation process works end-to-end. Test your Travel Rule message flows with counterparty CASPs. Document all test results and remediation actions.

  6. Evidence (Ongoing from Day 181). Establish your KPI dashboard, schedule quarterly rule reviews and book your first independent audit. The evidence phase never ends; it is the continuous improvement cycle that keeps your programme current as your business and the regulatory environment evolve.

Resourcing reality check. A crypto firm processing moderate transaction volumes typically needs a qualified MLRO, at least one dedicated compliance analyst for alert triage, and access to a technology or data specialist for analytics configuration. Smaller firms often underestimate the analyst resource required once monitoring is live and alert volumes become apparent. Building in a tuning sprint at the 90-day post-go-live mark to recalibrate thresholds and reduce false positives is a practical way to manage that pressure.

Grant Thornton's analysis of crypto compliance in 2026 confirms that enforcement actions and updated regulatory frameworks are raising expectations for governance, transaction monitoring and sanctions screening, making scalable, technology-driven programmes a baseline expectation rather than a differentiator.

Data privacy as a timeline constraint. GDPR-compliant data flows between your KYC platform, analytics tools and case-management system require documented data-sharing agreements and data protection impact assessments (DPIAs) before go-live. Factor four to six weeks for legal review of vendor data-processing agreements into your procurement timeline; this is consistently the step that delays integration.


How to build your implementation roadmap — overview diagram

How do you choose the right technology for AML controls?

Vendor selection for crypto AML technology is a procurement decision with long-term supervisory consequences. A tool that cannot produce logged, auditable evidence of its decisions is a liability in an FCA inspection, regardless of how sophisticated its underlying model is.

Build your RFP around these functional requirements:

  • Wallet risk scoring with entity-level labels (exchange, mixer, darknet market, sanctioned entity) and cross-chain coverage including Bitcoin, Ethereum and major Layer 2 networks.
  • Real-time and batch transaction screening with configurable risk thresholds by customer segment.
  • Travel Rule messaging capability with proof of live counterparty connections, not just a roadmap.
  • Case-management integration via API, with logged alert records that include the analyst's decision and timestamp.
  • Explainable risk scores: the system must be able to tell an analyst (and a supervisor) why a wallet received a particular risk rating.
  • Model governance documentation: how often is the underlying model retrained, who approves changes, and how are you notified?
  • Data protection: where is data processed and stored, and does the vendor's DPA meet UK GDPR requirements?
  • SLA commitments for uptime, alert latency and support response times, with contractual remedies.

Must-have contract clauses. Your vendor contract should include: a right for supervisors to access system logs and configuration records on request; a requirement for the vendor to notify you of material model changes before deployment; data retention and deletion obligations aligned to your five-year MLR requirement; and a termination clause that guarantees data portability so you are not locked in if you need to switch providers.

"Regulators frequently require a signed contract and evidence of integration with a Travel Rule provider when assessing authorisation files — not a letter of intent, not a roadmap, but a live integration." This expectation, documented in FATF and EU regulatory guidance, means your Travel Rule procurement must happen in parallel with your authorisation application, not after it.

Integrating blockchain analytics with existing systems. The most effective architecture connects your blockchain analytics platform directly to your transaction processing system so that every outgoing and incoming transfer triggers an automated wallet screen before settlement. Alerts feed into your case-management or AML system, where analysts triage them against the customer's risk profile and transaction history. Platforms like Elliptic's Lens combine wallet screening and transaction monitoring with configurable rules and produce logged records that support investigations and supervisory review. When evaluating any platform, ask for a demonstration of the audit trail a supervisor would actually see, not just the analyst-facing dashboard.

AI and machine learning: capability and caution. AI-driven transaction monitoring can reduce false positives significantly by learning from your firm's historical alert disposition patterns. The governance requirement is that you can explain every automated decision in plain language. Before deploying any ML model in a production AML workflow, document the model's training data, validation methodology, performance metrics and the human review process for edge cases. The FCA's risk-based supervisory approach means that a firm relying on an unexplainable black-box model to make CDD or monitoring decisions is taking on supervisory risk, not reducing it. AI is a powerful lever for sanctions compliance and monitoring at scale, but it requires the same governance rigour as any other control.

For firms evaluating advisory support alongside technology procurement, independent analysis of advisory alternatives can help frame the build-versus-buy decision before committing to a vendor.


How do you measure whether your AML controls are working?

A control that exists on paper but cannot demonstrate its effectiveness in data is not a control the FCA will accept. Your KPI framework should answer three questions: are alerts being generated at the right rate, are they being resolved correctly, and is the programme improving over time?

Operational KPIs to track monthly:

  • Alert volume by severity tier (high, medium, low) and by product or customer segment.
  • Alert-to-SAR conversion rate: the proportion of alerts that result in an internal suspicious activity report.
  • Time-to-investigation: median time from alert generation to analyst disposition.
  • False positive rate: the proportion of alerts closed as non-suspicious after review.
  • Travel Rule match rate: the proportion of transfers where originator/beneficiary data was successfully exchanged.
  • Cross-chain coverage: the percentage of transaction volume covered by your blockchain analytics tool across all chains your customers use.
  • SAR quality score: assessed through periodic sampling by the MLRO against NCA guidance.

Testing cadence:

  1. Quarterly rule review: pull alert volume and disposition data, identify rules generating disproportionate false positives or zero alerts, and adjust thresholds with documented rationale.
  2. Semi-annual backtest: run your current rule set against six months of historical transaction data to validate that known typologies would have been detected.
  3. Annual red-team exercise: simulate a money laundering scenario end-to-end, from customer onboarding through transaction monitoring to SAR submission, and document where the programme succeeded and where it failed.
  4. Annual independent audit: commission an external review of your AML programme against the MLRs and FCA supervisory expectations, with a written findings report and management response.

Present KPI trends to your board quarterly, not just the MLRO. Board oversight of AML effectiveness is a supervisory expectation, and the FCA will ask to see board minutes that demonstrate meaningful engagement with compliance metrics, not just a rubber-stamp approval of the annual report.

The intersection of cybersecurity and AML controls is increasingly relevant here: transaction monitoring systems that are compromised or manipulated by a threat actor can generate false negatives at scale. Include your AML technology stack in your cyber risk assessment and test for integrity as well as performance.


What do UK supervisors focus on when they inspect crypto AML programmes?

The FCA uses a strictly risk-based supervisory approach, which means firms assessed as higher ML/TF risk receive more intensive scrutiny. Supervisors do not work through a generic checklist; they focus on whether your controls are proportionate to your specific risk profile and whether you can evidence that they are working.

Primary supervisory focus areas:

  • Risk assessment quality: Is it firm-specific, current and used to drive control calibration? A generic template that does not reflect your actual products and customer base will be challenged.
  • CDD and EDD application: Supervisors pull customer files and check that the level of due diligence applied matches the customer's risk rating. Self-hosted wallet verification is a specific focus point.
  • Travel Rule capability: Can you demonstrate live message exchange with counterparty CASPs? A policy document without a working integration is not sufficient.
  • Transaction monitoring effectiveness: Supervisors review alert logs, triage records and SAR conversion rates. They look for evidence that analysts are making reasoned decisions, not just closing alerts.
  • SAR quality: The NCA and FCA both assess whether SARs contain sufficient information to be actionable. Thin, formulaic SARs are a red flag.

Inspection preparation checklist:

  • Compile your AML policy suite, risk assessment, MLRO terms of reference and board reporting pack.
  • Prepare a system access demonstration for your transaction monitoring and sanctions screening tools.
  • Have your REP-CRIM submission history and RegData records available.
  • Ensure your MLRO is available throughout the inspection and briefed on recent alert and SAR activity.
  • Prepare a remediation tracker showing any open findings from previous audits and their current status.

Enforcement consequences. The FCA has used its powers under the MLRs to cancel registrations, impose financial penalties and issue supervisory directions requiring firms to appoint independent monitors. Firms that receive a supervisory direction typically face a structured remediation programme with defined milestones and external oversight, which is significantly more disruptive and costly than proactive investment in a compliant programme. The Sumsub compliance guide identifies incomplete KYC evidence, Travel Rule readiness shortfalls and weak wallet attribution as the most common gaps that trigger regulatory action.

When responding to a supervisory request, acknowledge receipt promptly, provide a realistic timeline for document production and flag any gaps in your evidence proactively rather than waiting for the supervisor to identify them. A firm that demonstrates self-awareness about its control weaknesses and a credible remediation plan is in a materially better position than one that appears to have been caught unaware.


Key takeaways

Effective cryptocurrency compliance under UK law requires a documented, risk-calibrated programme that maps every control to a specific MLR obligation, FCA expectation or supervisory evidence requirement, and that can demonstrate its effectiveness through logged data and independent testing.

PointDetails
Register before you operateFCA registration under the MLRs is a prerequisite; operating without it carries criminal liability and reputational consequences.
Travel Rule is a day-one obligationSecure a signed Travel Rule provider contract and live integration before authorisation, not after; regulators check for this at application stage.
Evidence beats documentationSupervisors pull alert logs and case files, not just policies; build workflows that produce decision records automatically at every triage step.
AI amplifies monitoring but requires governanceBlockchain analytics and ML models reduce false positives at scale, but every automated decision must be explainable and subject to periodic model review.
Ai-thea supports programme design and vendor selectionAi-thea's AML consulting and technology matchmaking helps compliance teams convert regulatory obligations into operational controls and select the right technology stack.

The compliance gap that technology alone cannot close

There is a pattern Ai-thea observes repeatedly when working with crypto firms on AML programme design: the technology is often ahead of the governance. A firm will have procured a capable blockchain analytics platform, configured monitoring rules and integrated a Travel Rule solution, and then present to a supervisor with a board that cannot articulate the firm's ML/TF risk profile and an MLRO who has never presented a KPI dashboard to senior management.

The lesson is not that technology is insufficient. It is that technology without governance is an orphaned control. The FCA's risk-based approach is not primarily a technology assessment; it is a judgement about whether the people responsible for the programme understand the risks they are managing and have the authority and resource to act on what the technology tells them.

Three observations from programme implementations stand out. First, evidence over templates: firms that invest in building evidence-generating workflows from day one, rather than retrofitting documentation after the fact, consistently perform better in supervisory reviews. Second, integration before automation: connecting your analytics tools to your case-management system before you start tuning AI models means your model has clean, structured data to learn from. Rushing to deploy ML on top of a fragmented data architecture produces models that are both inaccurate and unexplainable. Third, board buy-in is not a soft requirement. The FCA will ask to see board minutes. If those minutes show that the board received a compliance report and asked no questions, that is a finding in itself.

AI and agentic analytics are genuinely changing what is possible in transaction monitoring and wallet attribution. The firms that will benefit most are those that have already built the governance infrastructure to absorb and act on what those tools surface. The technology is the lever; the governance is the fulcrum.


Ai-thea helps you design and implement crypto AML controls

Designing a compliant crypto AML programme from scratch, or remediating one that has fallen behind supervisory expectations, requires more than a policy template. It requires a clear view of the regulatory obligations, the right technology stack and a procurement process that produces contracts supervisors can inspect.

Heliolus AI - The AI Powered RegTech Directory

Ai-thea works with crypto firms, fintechs and compliance teams to design AML/CTF control frameworks mapped to FCA and MLR obligations, run structured RFP and vendor selection processes for blockchain analytics, Travel Rule and KYC technology, and deliver compliance training tailored to your team's role and risk profile. Whether you are preparing for FCA registration, responding to a supervisory finding or building out your programme ahead of a product launch, Ai-thea brings the regulatory knowledge and technology market expertise to accelerate the work. Speak to the team to discuss your programme priorities and find out how Ai-thea's AML consulting services can support your next phase.


Useful sources for UK crypto AML compliance

Use the sources below as primary references when drafting policies, evidencing supervisory files and tracking regulatory developments. Where possible, retain a dated screenshot of each page alongside your policy document to demonstrate that your procedures reflected current guidance at the time of drafting.

SourceWhat it coversHow to use it
FCA: Cryptoassets AML/CTF regimeFCA registration requirements, supervisory expectations, REP-CRIM reportingCite in your AML policy as the primary supervisory reference; retain dated screenshots
MLRs 2017 (legislation.gov.uk)Full statutory text of the Money Laundering RegulationsReference specific regulations (e.g. Reg. 28) in your policy and procedure documents
EBA guidance: ML/TF in the cryptoassets sectorCASP governance, risk factors, Travel Rule, restrictive measures screeningUse for cross-border due diligence standards and when assessing EU counterparty CASPs
MiCA KYC requirements (Zyphe)MiCA Arts. 68–73 CDD, ongoing monitoring, record keepingAlign your CDD standards for EU-facing activity; use as a benchmark for KYC programme design
TFR and AMLD6 guide (Finconduit)Travel Rule thresholds, self-hosted wallet obligations, AMLD6 criminal penaltiesReference when designing Travel Rule procedures and self-hosted wallet verification workflows
Grant Thornton: crypto compliance 2026Enforcement trends, technology expectations, governance benchmarksUse to support board-level business cases for compliance investment
Elliptic LensWallet screening and transaction monitoring capabilitiesUse as a benchmark when evaluating blockchain analytics vendors in your RFP
Sumsub: crypto AML guide 2026Common implementation gaps, KYC evidence, Travel Rule readinessUse to validate your gap analysis and prioritise remediation

A note on versioned evidence. Regulatory guidance pages are updated without notice. When you cite an FCA or EBA page in a policy document, record the URL, the date accessed and a brief description of the content you relied upon. If a supervisor later challenges whether your procedure reflected current guidance, a dated screenshot is far more persuasive than a bare URL.


FAQ

What is the AML rule for crypto in the UK?

The primary rule is the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, which require cryptoasset exchange providers and custodian wallet providers to register with the FCA, apply a risk-based approach, conduct customer due diligence, monitor transactions and submit SARs to the NCA.

What is an AML system for crypto?

An AML system for crypto is the combination of policies, procedures, technology and people that a firm uses to detect, prevent and report money laundering and terrorist financing. It typically includes a transaction monitoring engine, blockchain analytics for wallet risk scoring, sanctions screening, a case-management workflow and a SAR submission process.

What are AML controls?

AML controls are the specific measures a firm implements to manage its money laundering and terrorist financing risk. In the crypto context, they include customer due diligence, transaction monitoring, sanctions screening, Travel Rule compliance, self-hosted wallet verification, SAR reporting and independent testing of the overall programme.

What is the Travel Rule threshold for crypto transfers?

Under the Transfer of Funds Regulation, originator and beneficiary information must accompany crypto transfers at or above EUR 1,000, with additional verification requirements applying when the transfer involves a self-hosted (non-custodial) address. UK firms with EU-facing activity must account for these thresholds when designing their Travel Rule procedures.

Do UK crypto firms need to file SARs?

Yes. Under the Proceeds of Crime Act 2002, any person who knows or suspects that another person is engaged in money laundering must submit a SAR to the NCA. Crypto firms must have a documented internal reporting procedure, a nominated MLRO and a SAR register that records all internal reports and their outcomes.

This article provides general information about UK AML regulatory obligations and is not legal or compliance advice. Confirm current requirements with the FCA, your legal advisers or a qualified compliance professional before making programme decisions.