Blog Login
AML

Crypto KYC Requirements: What Exchanges and Crypto Companies Must Collect

A

Anzar Dewani

1 day ago

Crypto exchanges and other cryptocurrency businesses must collect specific information from customers as part of their KYC requirements. Here is exactly what must be collected, verified, and retained.

Crypto KYC Requirements: What Exchanges and Crypto Companies Must Collect

Crypto exchanges and other cryptocurrency businesses that qualify as Money Services Businesses are required to collect and verify customer information as part of their Customer Identification Program — the KYC component of their BSA/AML compliance obligations. Getting KYC right starts with knowing exactly what must be collected, how it must be verified, and how long it must be retained.

This article covers the specific data requirements for crypto KYC programs — what information to collect from individual and business customers, how to verify it, and what retention obligations apply.

Required Information for Individual Customers

At minimum, the Customer Identification Program rules require collection of the following for individual customers at onboarding.

Full legal name — as it appears on the customer's government-issued identification document.

Date of birth — required to verify that the customer is of legal age and to match against identity documents.

Residential address — a physical address, not a P.O. Box. This is used for verification, sanctions screening, and geographic risk assessment.

Identification number — either a government-issued ID number such as a passport number or driver's license number, or for US persons, a Social Security Number or Individual Taxpayer Identification Number.

These four fields — name, date of birth, address, and ID number — are the statutory minimum. Many crypto companies collect additional information for risk assessment purposes, including nationality, occupation, source of funds, and expected transaction volumes.

Required Information for Business Customers

For business customers, KYC requirements are more extensive. Required information includes the business's legal name and any trade names, principal place of business address, Employer Identification Number or equivalent tax identifier, business type and description of activities, and information about the beneficial owners who own or control the business.

Beneficial ownership collection requires identifying all individuals who own 25% or more of the business and the individual who has primary responsibility for managing the business, and collecting the same four CIP data elements for each of those individuals.

Verification Requirements

Collecting information is the first step — verifying it is the second. Verification means confirming that the information provided is accurate and that the customer is who they claim to be.

For individual customers, verification typically involves document verification — reviewing a government-issued photo ID to confirm it matches the information provided — combined with biometric verification such as liveness detection and facial comparison to confirm the document belongs to the person presenting it.

For business customers, verification involves reviewing formation documents and confirming the entity is registered as described, and verifying the identities of beneficial owners.

Sanctions Screening During KYC

All customers — individual and business — must be screened against applicable sanctions lists at onboarding. For US businesses, this includes at minimum the OFAC SDN List and OFAC's other sanctions programs. In the crypto context, OFAC has specifically sanctioned individual wallet addresses in addition to named persons and entities — so crypto KYC programs must screen against both name-based and address-based sanctions lists.

Enhanced Due Diligence for Higher-Risk Customers

Standard KYC applies to all customers. Enhanced Due Diligence applies to customers who present elevated risk — including Politically Exposed Persons, customers in high-risk jurisdictions, customers with high transaction volumes or unusual transaction patterns, and customers where standard verification does not resolve identity questions.

EDD typically involves collecting additional information about the source of funds, conducting more detailed background research, and requiring more frequent ongoing review.

Recordkeeping Requirements

All CIP information — the data collected and the verification steps taken — must be retained for five years after the customer relationship ends. This includes the original information collected, the verification documents reviewed, and documentation of the verification outcome.

Frequently Asked Questions

Can crypto companies use third-party vendors for KYC?

Yes. Many crypto companies use third-party KYC vendors — identity verification platforms — to automate document and biometric verification. Using a third-party vendor does not eliminate your compliance obligations — you remain responsible for your KYC program and for ensuring the vendor meets your requirements. Review vendor capabilities carefully, including their document coverage, fraud detection, and data security practices.

Do KYC requirements apply differently based on transaction size?

The BSA requires enhanced recordkeeping for transactions above certain thresholds — for example, enhanced due diligence for transactions suggesting structuring. However, the core KYC requirement to identify and verify customers applies to all customers, not just those above a transaction threshold. All customers must be identified at onboarding regardless of their initial transaction size.

How ComplyOne Helps

ComplyOne helps crypto companies design KYC programs that satisfy BSA requirements — from Customer Identification Program policies through verification workflows, EDD procedures, recordkeeping, and third-party vendor oversight — through advisory services, compliance technology, or both.

 

 

Talk to the ComplyOne team to get started.

The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.

Share this article:

Related Articles