An on-ramp API splits compliance between the provider and you. Who runs KYC, KYB, KYT, sanctions, and the travel rule, and what stays on your side.
A crypto on-ramp is generally regulated as a money transmitter or a virtual asset service provider, so it must run KYC, AML, sanctions screening, and transaction monitoring on everyone who pays in. When you integrate one through an API, the provider runs those checks. You still own the data you collect, the customers you bring, and your own licensing questions.
This article is general information, not legal advice. Compliance obligations depend on your jurisdiction, your business model, and your contract with the provider. Talk to counsel before you rely on any of it.
Seven checks, each with a different job.
| Term | What it means | When it runs |
|---|---|---|
| KYC (know your customer) | Verifying an individual's identity | Onboarding, and again when data changes |
| KYB (know your business) | Verifying a company, its owners, and its directors | Onboarding, and on periodic review |
| AML (anti-money laundering) | The program of policies, controls, and reporting that prevents laundering | Always |
| CFT (countering the financing of terrorism) | The same program, aimed at terrorist financing | Always |
| KYT (know your transaction) | Monitoring each payment for unusual patterns | Every transaction |
| Sanctions screening | Checking people, companies, and wallet addresses against lists like OFAC's SDN list | Onboarding and every transaction |
| Travel rule | Passing originator and beneficiary data with a transfer between providers | Transfers above the local threshold |
KYC and KYB answer "who is this?". KYT answers "does this payment make sense for them?". What is KYB goes deeper on business checks, and the travel rule for off-ramps covers thresholds by country.
Four primary sources set the frame. Read them directly; summaries, including this one, drop detail.
The pattern is the same everywhere: know who's paying, watch what they do, screen against sanctions, keep records, and report what looks wrong. What is a VASP explains how the FATF definition maps onto local licenses.
The provider runs the regulated checks. You run your business honestly on top of them. The split below is typical; your contract and your jurisdiction decide the real one.
| Task | On-ramp provider | Your company |
|---|---|---|
| Collect identity and business data | Defines what's required | Collects it from your users, accurately |
| Verify identity (KYC) and businesses (KYB) | Runs the checks and decides | Passes the data and the documents through |
| Sanctions screening | Screens customers, payers, and wallets | Doesn't onboard people you know are sanctioned |
| Transaction monitoring (KYT) | Monitors and holds suspicious payments | Answers requests for information |
| Suspicious activity reports | Files them with its regulator | Reports concerns through the provider's channel |
| Travel rule data | Exchanges it with other providers | Supplies accurate sender and recipient details |
| Terms of service | Publishes them | Makes sure each customer accepts them |
| Your own licensing | Not its responsibility | Yours to assess with counsel |
| End customers behind your customers | Requires them to be registered | Registers them; doesn't pool them |
Two rows trip people up. The first is data quality: the provider verifies what you send, so a sloppy onboarding form becomes a compliance problem downstream. The second is the last row, covered next.
Nesting is moving money for a party the provider can't see. If one customer's account carries deposits that economically belong to many other businesses or people, and the provider never onboarded them, the structure is nested.
Signs of nesting:
Regulators treat this as a way to hide who's really behind a payment, which is why providers prohibit it. The fix is visibility: register each end customer with the provider, or have the business that serves them onboard as its own direct customer.
Maybe. It depends on what your product does with the money, and only a lawyer who has read your flow of funds can answer it.
The questions that usually decide it:
A product that only passes data to a licensed provider, with funds moving straight from the payer to the provider and stablecoins straight to the user's own wallet, sits in a different place than one that collects funds first. Do merchants need a license to accept stablecoins walks through a related version of the question.
Six stages, in order:
The stages after onboarding are where integrations break. A product that handles approval but has no screen for "in review" will generate support tickets on day one. Real-time transaction monitoring shows a flagged payment from start to finish.
Don't build a table of rules per country. It goes stale. Build a checklist of what varies, and ask the provider how it handles each one in your markets:
Write the answers into your vendor file. Stablecoin payments provider due diligence has the wider set of 30 questions.
BlindPay handles the compliance layer: you collect the data, and BlindPay verifies it. Every payment flows through a verified customer.
on_hold. The compliance team reviews each one and may send a request for information. If it isn't answered within 24 hours, the payment may be refunded to the sender.customer.update webhook signals compliance_request, and you fetch and answer the request with the RFI endpoints.The details are in the docs for KYC requirements, on-hold transactions, and nested payments.
When BlindPay is the right fit: you want compliance handled inside the API, with KYC, KYB, monitoring, and holds visible as statuses and webhooks you can build screens around. When it isn't: you want to run your own identity verification and only buy liquidity, or your business falls under BlindPay's prohibited activities.
Draw your flow of funds on one page: where the payer's money goes, who holds it at each step, and whose wallet the stablecoins reach. Mark who verifies each party. Take that page to your provider and your lawyer. Most compliance surprises show up as a box on that page that nobody owns.
If you're still choosing a provider, business vs consumer crypto on-ramps explains why business on-ramps verify more than consumer ones. Integrating a crypto on-ramp API shows where the KYC, hold, and request-for-information statuses appear in code.
This article is general information, not legal, tax, or financial advice. Regulations change, and obligations depend on your jurisdiction and contracts; confirm with qualified counsel.
Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.
A side-by-side comparison of automated and manual KYC/KYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.
How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.