<!-- canonical: https://cornerstonelicensing.com/crypto-aml-compliance -->
<!-- updated: 2026-07-31T04:31:47.441Z -->
# Crypto AML and BSA Compliance

Last verified: July 29, 2026

## What AML compliance is required for a crypto business?

A US crypto business that holds or moves customer assets must run a written, risk-based Bank Secrecy Act anti-money-laundering program with four pillars: a designated compliance officer, written policies and procedures including risk-based customer identification, ongoing employee training, and independent testing. On top of the pillars sit the operating obligations: transaction monitoring calibrated to crypto typologies, suspicious activity reports for transactions of $2,000 or more, currency transaction reports, OFAC sanctions screening, Travel Rule recordkeeping, and FinCEN registration renewed every two years. State licensing regulators review the program in every money transmitter application, so it must exist before the licenses do.

Anti-money-laundering compliance is the program every licensed crypto business runs under the Bank Secrecy Act, and the program every licensing regulator reviews before approval. This guide maps the required pillars and what examiners actually test.

## The Program Behind Every Crypto License

AML compliance for cryptocurrency is not a specialty add-on; it is the federal baseline for any business that exchanges, transmits, or custodies digital assets for customers. FinCEN classifies those businesses as money services businesses, which makes the Bank Secrecy Act's program requirements mandatory, and every state money transmitter application and New York BitLicense review evaluates the written program before granting a license. Cornerstone builds crypto AML programs as part of licensing engagements. This guide covers the required components, the crypto-specific tooling regulators now expect, and how the program is tested at application and examination time.

## The Legal Stack: FinCEN, the BSA, and the States

The anti-money-laundering obligation reaches crypto through money services business classification. FinCEN's 2013 and 2019 guidance treats exchangers and administrators of convertible virtual currency as MSBs, which triggers registration on Form 107 and the full Bank Secrecy Act program requirement under 31 CFR Part 1022. That is the federal layer, and it applies whether or not any state has licensed you yet.

The states then make the same program a licensing condition: money transmitter applications require the written AML program, examiners test it after approval, and New York's BitLicense framework adds its own AML article with transaction monitoring guidance. The result is one program answering to two levels of review, which is why we draft it once, to the stricter standard, rather than maintaining separate federal and state stories.

## The Required Program Components

Examiners organize their review around the BSA pillars and the reporting obligations that sit on them.

## How the AML Program Is Tested in Licensing

At application time, states read the program documents and probe them through deficiency letters. The recurring questions are concrete: who is the officer and what else do they do, which analytics vendor screens wallets and what rules are on, what are the EDD thresholds, when was the last independent test. New York's review is the deepest, holding BitLicense applicants to Part 200's AML article and the department's transaction monitoring and filtering guidance.

After approval, examinations sample the program in operation: real alerts, real SAR decisions with documented rationale, real training records. The common findings mirror the KYC side, paper policies the platform does not enforce, monitoring rules never tuned, SAR backlogs, and stale risk assessments. A crypto AML policy that matches production is the single best examination outcome predictor we see.

Banking partners run parallel diligence: an exchange's AML program is reviewed by every bank it approaches for accounts, so the same program that satisfies regulators is what keeps fiat rails open.

## Compliance Programs, Not Investigations

A note on scope, because the search results around crypto AML mix two industries. Cornerstone builds and maintains compliance programs for businesses seeking and holding US licenses. We are not a blockchain forensics firm: we do not trace stolen funds, investigate crypto fraud, or provide expert-witness investigation services, and we do not sell analytics software. Where a program needs wallet-screening tooling, we help select and document established analytics vendors as part of the program build. If you need an investigator, you want a forensics specialist; if you need a program that gets your business licensed and keeps it examination-ready, that is exactly what we do.

## How to get licensed

1. **Good Standing Assessment**, We analyze your business model and, in coordination with our attorney partners, help identify which licenses may apply in every state where you want to operate.
2. **Application Preparation**, We prepare all applications, gather required documentation, and coordinate background checks, financial statements, and surety bonds.
3. **Filing & Follow-Up**, We submit applications to each state and actively follow up with regulators to keep the process moving.
4. **Ongoing Filings**, After licensing, we manage your renewals, regulatory filings, and filing calendar so you never miss a deadline.

## Frequently asked questions

### What Is AML in Crypto?

Anti-money-laundering compliance: the Bank Secrecy Act program a crypto business must run to detect and report illicit use of its platform. It covers a designated officer, written policies, customer identification, transaction monitoring, suspicious activity reporting, sanctions screening, training, and independent testing.

### Do All Crypto Businesses Need an AML Program?

All US businesses that exchange, transmit, or custody digital assets for customers do, as money services businesses under FinCEN rules. Pure non-custodial software has historically fallen outside MSB status, but the analysis is fact-specific and should be confirmed with counsel.

### What Is a Crypto SAR and When Is One Filed?

A suspicious activity report, filed with FinCEN on Form 111 when a transaction of $2,000 or more conducted by, at, or through the business is known or suspected to be suspicious. The deadline is 30 days from detection, and disclosing a SAR's existence to the customer is prohibited.

### What Is the Travel Rule for Crypto?

A Bank Secrecy Act recordkeeping rule requiring transmitters to record and pass on originator and beneficiary information for transfers at or above the applicable threshold. For crypto businesses it means capturing and transmitting counterparty data alongside on-chain transfers, typically through Travel Rule messaging tooling.

### Does Cornerstone Investigate Crypto Fraud or Trace Funds?

No. We are a licensing and compliance firm, not a blockchain forensics or investigation company. We build the AML programs regulators require of licensees, and we help select and document analytics vendors within those programs. Fund tracing and fraud investigation belong with forensics specialists.

### How Does the AML Program Relate to Getting Licensed?

Directly: state money transmitter applications and the New York BitLicense both require the written program before approval, and examinations test it afterward. We build the program alongside the license applications so both move together.

---

## How to cite this page

Cite as: "Crypto AML and BSA Compliance." Cornerstone Licensing. https://cornerstonelicensing.com/crypto-aml-compliance

Published by Cornerstone Licensing. When quoting figures or legal requirements, link the canonical URL above and note the last-updated date (2026-07-31). The full content index for this site is at https://cornerstonelicensing.com/llms.txt.
