
How to Set Up a Crypto Business Compliance Function

A crypto business rarely fails compliance because it lacks a policy template. It fails because no one owns the controls, customer risk decisions are inconsistent, transaction alerts are ignored, and the board learns about the exposure after a banking partner or regulator raises it. To set up crypto business compliance function properly, founders must build an operating capability, not a folder of documents prepared for a licence application.
For EU-facing firms, this is particularly urgent. MiCA has changed the standard for crypto-asset service providers, while anti-money laundering obligations, sanctions risk, the Travel Rule, data protection and operational resilience requirements continue to shape whether a business can launch, retain banking and scale. The right design depends on your services, jurisdictions, customer profile and growth plan. However, the underlying principle is consistent: compliance must be independent enough to challenge the business, yet close enough to help it make commercially workable decisions.
Start with the regulated business model
Before appointing a compliance officer or purchasing monitoring software, define exactly what the company will do. A custodial wallet provider, exchange, broker, token issuer, OTC desk and payment-focused platform face different regulatory triggers and risk profiles. Combining several services within one product can create obligations that were not apparent in the original commercial plan.
Map the customer journey from onboarding to exit. Identify where fiat enters and leaves the platform, how crypto assets are transferred, whether the firm controls private keys, which countries are targeted, and whether third parties perform any critical function. This exercise should also establish which entity contracts with customers and which group companies provide technology, marketing, liquidity or support.
Jurisdiction selection cannot be separated from this analysis. A lower-cost incorporation route may become expensive if it does not support the permissions, banking relationships or EU passporting strategy the business needs. Conversely, pursuing a full authorisation too early can absorb capital and management time where a narrower launch model would be lawful and commercially sensible. The route should be chosen against the actual operating model, not a generic list of crypto-friendly jurisdictions.
Set up a crypto business compliance function around ownership
A credible compliance function needs a clear reporting line, defined authority and documented decisions. Regulators will look beyond job titles. They will ask who can stop a high-risk customer from being onboarded, who approves enhanced due diligence, who investigates suspicious activity, and whether that person can act without sales pressure.
For an early-stage business, the compliance function may begin with a suitably qualified MLRO or compliance lead supported by external specialists. This can be efficient where transaction volumes are low and the scope is tightly controlled. It does not remove management responsibility. Directors remain responsible for ensuring the function has sufficient resources, receives meaningful management information and is able to escalate concerns.
As the business grows, separate responsibilities become necessary. The second line should oversee the framework and challenge first-line operations. Operations should execute customer due diligence and alert handling under defined procedures. Internal audit, whether in-house or outsourced, should independently test whether controls work in practice. Combining all three functions in one person may be unavoidable at launch, but it should be treated as a temporary arrangement with safeguards for conflicts and independent review.
A practical governance model should specify the board or senior management committee responsible for financial crime risk, the MLRO’s access to decision-makers, delegated approval limits and escalation timescales. Keep a decision log for difficult cases. When a regulator asks why a politically exposed person, high-risk jurisdiction customer or complex corporate structure was accepted, a clear contemporaneous rationale matters more than a retrospective explanation.
Build the framework before customer volume arrives
Policies are not the function itself, but they translate legal duties into repeatable action. The priority documents usually include the AML and counter-terrorist financing policy, enterprise-wide risk assessment, customer risk methodology, sanctions controls, customer due diligence procedures, suspicious activity reporting procedure, complaints process, conflicts policy, data protection documentation and record-retention rules.
For a crypto business, these documents must address crypto-specific risks. The framework should explain how the firm assesses wallet exposure, uses blockchain analytics, handles self-hosted wallet transfers where relevant, applies Travel Rule requirements, detects sanctions evasion and investigates typologies such as layering through mixers, rapid chain-hopping or use of high-risk decentralised finance protocols.
Avoid copying a generic AML policy that refers vaguely to “digital assets”. It will not tell an analyst what to do when a customer deposits assets linked to a sanctioned address, when a screening match cannot be resolved, or when a customer’s source-of-wealth explanation does not align with on-chain activity. Procedures should contain decision points, ownership, evidence requirements and escalation routes.
The risk assessment is the foundation. It should assess customers, products, delivery channels, geographies, transaction patterns and outsourcing. Its conclusions must drive the controls. If the assessment identifies elevated exposure from non-face-to-face onboarding, for example, the onboarding process should demonstrate compensating checks rather than merely acknowledge the risk.
Choose systems that support the operating model
Technology should follow the control design. Buying several well-known compliance tools without a workflow can create duplicate alerts, unexplained risk scores and a false sense of security. Select systems based on the firm’s volumes, supported chains, customer types, integration capacity and reporting requirements.
At minimum, a scalable set-up normally needs identity verification and screening, customer risk scoring, blockchain transaction monitoring, case management and secure record keeping. The key question is not whether a supplier produces alerts. It is whether the business can evidence how alerts are triaged, investigated, closed and escalated.
Outsourcing is permitted in many areas, but accountability cannot be outsourced. Due diligence on providers should cover their legal status, data processing, service levels, model limitations, business continuity arrangements and audit rights. If an external provider handles onboarding or monitoring, the firm still needs access to underlying evidence and a process for testing quality.
Make onboarding and monitoring operational disciplines
Customer due diligence should not be treated as a one-time gateway. At onboarding, collect and verify information proportionate to the risk, establish beneficial ownership for corporate customers, screen relevant parties and understand the expected use of the service. Higher-risk relationships require enhanced due diligence, including stronger evidence of source of funds or source of wealth where appropriate.
The difficult commercial issue is calibration. Excessive friction can damage conversion and push legitimate customers towards competitors. Weak checks, however, can lead to financial crime exposure, rejected banking applications and regulatory action. Segment customers intelligently instead of applying the same process to every user. A regulated institutional client with transparent ownership needs a different review path from a retail customer making large, inconsistent transfers through high-risk counterparties.
Ongoing monitoring must compare actual activity against the expected profile. Cases need service-level deadlines, quality assurance and a documented suspicious activity reporting route. Compliance should report trends to management, including alert volumes, ageing cases, high-risk customer numbers, sanctions matches, rejected applicants and recurring control failures. These figures reveal whether the framework is functioning or merely producing paperwork.
Test the function before a regulator or bank does
A compliance programme becomes credible through evidence. Train staff according to their role, retain attendance and assessment records, and refresh training when products, risks or rules change. Sales, customer support and operations staff need to understand their own escalation duties, not just complete an annual AML module.
Conduct periodic monitoring and independent testing. Sample onboarding files, review alert closures, test sanctions screening, check Travel Rule data, verify record retention and examine whether board reporting leads to action. Findings should have owners, deadlines and formal closure evidence. Repeated findings are a governance problem, not a minor administrative issue.
Prepare for external scrutiny from the outset. A licence application, bank due diligence exercise or regulatory inspection may require the business to demonstrate not only its policies but also its staffing, governance, systems, supplier oversight and live operating records. Building this evidence trail before launch is faster and less costly than recreating it under pressure.
For founders weighing a build-versus-buy route, a ready-made operating vehicle can shorten the corporate and documentation phase, but it does not eliminate the need to align controls with the new business model. Licences, governance arrangements and banking relationships must be assessed carefully before acquisition.
The most useful next step is to run a gap assessment against the exact services you intend to provide and the markets you intend to serve. A focused plan, accountable owners and realistic implementation dates will give your compliance function the credibility needed to support growth rather than delay it.



Comments