Short answer
A US crypto business that holds or moves customer assets must run a risk-based anti-money-laundering program under FinCEN's money services business rules, and that program must include reasonable procedures for verifying customer identification. MSBs are not under the formal bank CIP rule, but recordkeeping rules, OFAC sanctions screening, New York's BitLicense regulations, and state licensing reviews each force verification in practice, so licensed platforms collect and verify name, date of birth, address, and an identification number as the standard baseline. Regulators review the written KYC procedures in every money transmitter and BitLicense application.
KYC for crypto is not a product feature; it is a condition of being licensable. The federal baseline is FinCEN's MSB AML rule: a written, risk-based program with identity-verification procedures reasonable and practicable for the business's risk, plus sanctions and politically-exposed-person screening and enhanced due diligence for higher-risk customers at documented thresholds. Bank Secrecy Act recordkeeping and Travel Rules add verified-identity requirements for covered transmittals, and New York's BitLicense regulations spell out customer identification expectations expressly. Crypto adds its own layer, wallet screening and source-of-funds checks through blockchain analytics, which examiners increasingly expect to see running in production.
The state layer is where KYC gets tested. Money transmitter applications require the written procedures up front; New York's BitLicense reviews them in depth; and post-licensure examinations sample real onboarding files. A program that exists on paper but is not wired into onboarding is one of the most common examination findings. The full requirement set, and how it fits into a licensing application, is at KYC verification for crypto businesses, with the monitoring and reporting side at crypto AML and BSA compliance.
Related
More questions about Cryptocurrency licensing
Browse more questions and answers.