[{"data":1,"prerenderedAt":830},["ShallowReactive",2],{"content-\u002Fresources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what":3,"resources-category-crypto-on-ramp-compliance-who-owns-what":751},{"id":4,"title":5,"authors":6,"body":7,"categories":6,"category":718,"categoryType":6,"compare":6,"contributors":6,"date":719,"description":720,"extension":721,"faq":722,"howto":6,"isBlog":741,"isChangelog":741,"meta":742,"navigation":744,"path":745,"pillar":741,"products":6,"rawbody":746,"role":6,"seo":747,"seoTitle":748,"stem":749,"thumbnail":6,"updated":719,"__hash__":750},"content\u002Fresources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what.md","Who owns compliance when you integrate a crypto on-ramp API? KYC, KYB, KYT, and holds",null,{"type":8,"value":9,"toc":703},"minimark",[10,14,20,25,44,48,51,150,164,168,171,233,241,245,248,363,366,370,373,376,390,393,397,400,403,418,426,430,433,471,479,483,486,533,537,575,583,587,590,647,664,678,682,685,698],[11,12,13],"p",{},"A crypto on-ramp is generally regulated as a money transmitter or a virtual asset service provider, so it must run KYC, AML, sanctions screening, and transaction monitoring on everyone who pays in. When you integrate one through an API, the provider runs those checks. You still own the data you collect, the customers you bring, and your own licensing questions.",[11,15,16],{},[17,18,19],"em",{},"This article is general information, not legal advice. Compliance obligations depend on your jurisdiction, your business model, and your contract with the provider. Talk to counsel before you rely on any of it.",[21,22,24],"h2",{"id":23},"key-takeaways","Key takeaways",[26,27,28,32,35,38,41],"ul",{},[29,30,31],"li",{},"The provider is the regulated party for the conversion. It verifies identities, screens sanctions, monitors transactions, and files reports.",[29,33,34],{},"You collect the data, keep it accurate, and make sure only verified customers pay through your account.",[29,36,37],{},"Every party whose money moves needs to be visible to the provider. Pooling unregistered end customers under your account is nesting.",[29,39,40],{},"Holds are part of the system. Plan who answers a request for information, and how fast.",[29,42,43],{},"Whether you need your own license depends on whether you ever take possession of the money. That's a question for a lawyer, not a blog post.",[21,45,47],{"id":46},"what-compliance-checks-does-a-crypto-on-ramp-run","What compliance checks does a crypto on-ramp run?",[11,49,50],{},"Seven checks, each with a different job.",[52,53,54,70],"table",{},[55,56,57],"thead",{},[58,59,60,64,67],"tr",{},[61,62,63],"th",{},"Term",[61,65,66],{},"What it means",[61,68,69],{},"When it runs",[71,72,73,85,96,107,117,128,139],"tbody",{},[58,74,75,79,82],{},[76,77,78],"td",{},"KYC (know your customer)",[76,80,81],{},"Verifying an individual's identity",[76,83,84],{},"Onboarding, and again when data changes",[58,86,87,90,93],{},[76,88,89],{},"KYB (know your business)",[76,91,92],{},"Verifying a company, its owners, and its directors",[76,94,95],{},"Onboarding, and on periodic review",[58,97,98,101,104],{},[76,99,100],{},"AML (anti-money laundering)",[76,102,103],{},"The program of policies, controls, and reporting that prevents laundering",[76,105,106],{},"Always",[58,108,109,112,115],{},[76,110,111],{},"CFT (countering the financing of terrorism)",[76,113,114],{},"The same program, aimed at terrorist financing",[76,116,106],{},[58,118,119,122,125],{},[76,120,121],{},"KYT (know your transaction)",[76,123,124],{},"Monitoring each payment for unusual patterns",[76,126,127],{},"Every transaction",[58,129,130,133,136],{},[76,131,132],{},"Sanctions screening",[76,134,135],{},"Checking people, companies, and wallet addresses against lists like OFAC's SDN list",[76,137,138],{},"Onboarding and every transaction",[58,140,141,144,147],{},[76,142,143],{},"Travel rule",[76,145,146],{},"Passing originator and beneficiary data with a transfer between providers",[76,148,149],{},"Transfers above the local threshold",[11,151,152,153,158,159,163],{},"KYC and KYB answer \"who is this?\". KYT answers \"does this payment make sense for them?\". ",[154,155,157],"a",{"href":156},"\u002Fresources\u002Fmore\u002Fwhat-is-kyb","What is KYB"," goes deeper on business checks, and ",[154,160,162],{"href":161},"\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps","the travel rule for off-ramps"," covers thresholds by country.",[21,165,167],{"id":166},"what-do-regulators-expect-from-on-ramps","What do regulators expect from on-ramps?",[11,169,170],{},"Four primary sources set the frame. Read them directly; summaries, including this one, drop detail.",[26,172,173,193,204,215],{},[29,174,175,179,180,186,187,192],{},[176,177,178],"strong",{},"FinCEN (US)."," The ",[154,181,185],{"href":182,"rel":183},"https:\u002F\u002Fwww.fincen.gov\u002Fresources\u002Fstatutes-regulations\u002Fguidance\u002Fapplication-fincens-regulations-certain-business-models",[184],"nofollow","2019 guidance on convertible virtual currency"," treats businesses that accept and transmit virtual currency as money transmitters, with registration, AML program, recordkeeping, and reporting duties. You can check a provider's registration in the ",[154,188,191],{"href":189,"rel":190},"https:\u002F\u002Fwww.fincen.gov\u002Fmsb-registrant-search",[184],"MSB registrant search",".",[29,194,195,179,198,203],{},[176,196,197],{},"OFAC (US).",[154,199,202],{"href":200,"rel":201},"https:\u002F\u002Fofac.treasury.gov\u002Fmedia\u002F913571\u002Fdownload?inline",[184],"sanctions compliance guidance for the virtual currency industry"," expects screening of customers and wallet addresses, and a risk-based sanctions program.",[29,205,206,179,209,214],{},[176,207,208],{},"FATF (global).",[154,210,213],{"href":211,"rel":212},"https:\u002F\u002Fwww.fatf-gafi.org\u002Fen\u002Fpublications\u002FFatfrecommendations\u002FGuidance-rba-virtual-assets-2021.html",[184],"updated guidance on virtual assets and VASPs"," sets the standard most countries copy: customer due diligence, monitoring, and the travel rule.",[29,216,217,220,221,226,227,232],{},[176,218,219],{},"EU."," ",[154,222,225],{"href":223,"rel":224},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2023\u002F1114\u002Foj",[184],"MiCA"," requires crypto-asset service providers to be authorized, and the ",[154,228,231],{"href":229,"rel":230},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2023\u002F1113\u002Foj",[184],"Transfer of Funds Regulation"," applies the travel rule to crypto transfers with no minimum amount.",[11,234,235,236,240],{},"The pattern is the same everywhere: know who's paying, watch what they do, screen against sanctions, keep records, and report what looks wrong. ",[154,237,239],{"href":238},"\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp","What is a VASP"," explains how the FATF definition maps onto local licenses.",[21,242,244],{"id":243},"who-is-responsible-for-what-when-you-integrate-an-on-ramp-api","Who is responsible for what when you integrate an on-ramp API?",[11,246,247],{},"The provider runs the regulated checks. You run your business honestly on top of them. The split below is typical; your contract and your jurisdiction decide the real one.",[52,249,250,263],{},[55,251,252],{},[58,253,254,257,260],{},[61,255,256],{},"Task",[61,258,259],{},"On-ramp provider",[61,261,262],{},"Your company",[71,264,265,276,287,297,308,319,330,341,352],{},[58,266,267,270,273],{},[76,268,269],{},"Collect identity and business data",[76,271,272],{},"Defines what's required",[76,274,275],{},"Collects it from your users, accurately",[58,277,278,281,284],{},[76,279,280],{},"Verify identity (KYC) and businesses (KYB)",[76,282,283],{},"Runs the checks and decides",[76,285,286],{},"Passes the data and the documents through",[58,288,289,291,294],{},[76,290,132],{},[76,292,293],{},"Screens customers, payers, and wallets",[76,295,296],{},"Doesn't onboard people you know are sanctioned",[58,298,299,302,305],{},[76,300,301],{},"Transaction monitoring (KYT)",[76,303,304],{},"Monitors and holds suspicious payments",[76,306,307],{},"Answers requests for information",[58,309,310,313,316],{},[76,311,312],{},"Suspicious activity reports",[76,314,315],{},"Files them with its regulator",[76,317,318],{},"Reports concerns through the provider's channel",[58,320,321,324,327],{},[76,322,323],{},"Travel rule data",[76,325,326],{},"Exchanges it with other providers",[76,328,329],{},"Supplies accurate sender and recipient details",[58,331,332,335,338],{},[76,333,334],{},"Terms of service",[76,336,337],{},"Publishes them",[76,339,340],{},"Makes sure each customer accepts them",[58,342,343,346,349],{},[76,344,345],{},"Your own licensing",[76,347,348],{},"Not its responsibility",[76,350,351],{},"Yours to assess with counsel",[58,353,354,357,360],{},[76,355,356],{},"End customers behind your customers",[76,358,359],{},"Requires them to be registered",[76,361,362],{},"Registers them; doesn't pool them",[11,364,365],{},"Two rows trip people up. The first is data quality: the provider verifies what you send, so a sloppy onboarding form becomes a compliance problem downstream. The second is the last row, covered next.",[21,367,369],{"id":368},"what-is-nesting-and-why-do-on-ramps-prohibit-it","What is nesting, and why do on-ramps prohibit it?",[11,371,372],{},"Nesting is moving money for a party the provider can't see. If one customer's account carries deposits that economically belong to many other businesses or people, and the provider never onboarded them, the structure is nested.",[11,374,375],{},"Signs of nesting:",[26,377,378,381,384,387],{},[29,379,380],{},"Funds in the account belong to someone other than the onboarded customer.",[29,382,383],{},"Invoices or contracts name a different entity than the account holder.",[29,385,386],{},"One account collects for several underlying businesses.",[29,388,389],{},"Each sub-account or virtual account represents a different third party's money.",[11,391,392],{},"Regulators treat this as a way to hide who's really behind a payment, which is why providers prohibit it. The fix is visibility: register each end customer with the provider, or have the business that serves them onboard as its own direct customer.",[21,394,396],{"id":395},"do-you-need-your-own-license-if-you-use-an-on-ramp-api","Do you need your own license if you use an on-ramp API?",[11,398,399],{},"Maybe. It depends on what your product does with the money, and only a lawyer who has read your flow of funds can answer it.",[11,401,402],{},"The questions that usually decide it:",[404,405,406,409,412,415],"ol",{},[29,407,408],{},"Does money ever land in an account you control, even for a moment?",[29,410,411],{},"Do you hold stablecoins or fiat on behalf of users?",[29,413,414],{},"Do you set the exchange rate, or does the provider?",[29,416,417],{},"Are your users individuals, businesses, or both, and in which countries?",[11,419,420,421,425],{},"A product that only passes data to a licensed provider, with funds moving straight from the payer to the provider and stablecoins straight to the user's own wallet, sits in a different place than one that collects funds first. ",[154,422,424],{"href":423},"\u002Fresources\u002Fmore\u002Fdo-merchants-need-a-license-to-accept-stablecoins","Do merchants need a license to accept stablecoins"," walks through a related version of the question.",[21,427,429],{"id":428},"what-does-a-good-on-ramp-compliance-flow-look-like","What does a good on-ramp compliance flow look like?",[11,431,432],{},"Six stages, in order:",[404,434,435,441,447,453,459,465],{},[29,436,437,440],{},[176,438,439],{},"Onboarding."," Collect the data, accept the terms, run KYC or KYB.",[29,442,443,446],{},[176,444,445],{},"Risk scoring."," Higher-risk countries, business types, or structures get enhanced review.",[29,448,449,452],{},[176,450,451],{},"Limits."," Each verification tier gets per-transaction, daily, and monthly limits.",[29,454,455,458],{},[176,456,457],{},"Monitoring."," Every payin is screened and scored as it happens.",[29,460,461,464],{},[176,462,463],{},"Holds and requests for information."," Flagged payments pause for a human, who may ask you questions.",[29,466,467,470],{},[176,468,469],{},"Decision."," Release, refund, or escalate, and keep the record.",[11,472,473,474,478],{},"The stages after onboarding are where integrations break. A product that handles approval but has no screen for \"in review\" will generate support tickets on day one. ",[154,475,477],{"href":476},"\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments","Real-time transaction monitoring"," shows a flagged payment from start to finish.",[21,480,482],{"id":481},"how-should-you-think-about-compliance-across-countries","How should you think about compliance across countries?",[11,484,485],{},"Don't build a table of rules per country. It goes stale. Build a checklist of what varies, and ask the provider how it handles each one in your markets:",[26,487,488,498,504,510,516,522],{},[29,489,490,493,494,192],{},[176,491,492],{},"Licensing regime."," Money transmitter, VASP, payment institution, or something new, like Brazil's VASP rules covered in ",[154,495,497],{"href":496},"\u002Fresources\u002Fmore\u002Fpsav-brazil-explained","PSAV Brazil explained",[29,499,500,503],{},[176,501,502],{},"Identity documents and tax IDs."," CPF and CNPJ in Brazil, CUIT and CUIL in Argentina, NIT in Colombia.",[29,505,506,509],{},[176,507,508],{},"Enhanced review."," Which countries trigger manual checks.",[29,511,512,515],{},[176,513,514],{},"Travel rule thresholds."," These differ, and some markets apply the rule with no minimum.",[29,517,518,521],{},[176,519,520],{},"Data protection."," Where identity data is stored and who processes it.",[29,523,524,527,528,532],{},[176,525,526],{},"Stablecoin rules."," Some markets regulate the token itself, like the US under the ",[154,529,531],{"href":530},"\u002Fresources\u002Fmore\u002Fgenius-act-for-businesses","GENIUS Act"," and the EU under MiCA.",[21,534,536],{"id":535},"what-12-questions-should-you-ask-a-provider-about-compliance","What 12 questions should you ask a provider about compliance?",[404,538,539,542,545,548,551,554,557,560,563,566,569,572],{},[29,540,541],{},"Which licenses or registrations do you hold, in which entities, and where can I verify them?",[29,543,544],{},"Who verifies identity: you, or a vendor you rely on?",[29,546,547],{},"Which fields and documents are required for KYC and for KYB?",[29,549,550],{},"How long do automated and manual reviews take?",[29,552,553],{},"Which countries trigger enhanced review, and which can't onboard at all?",[29,555,556],{},"What are the default limits per tier, and how do customers raise them?",[29,558,559],{},"Do you screen wallet addresses as well as people?",[29,561,562],{},"How are flagged payments held, and how will you contact us?",[29,564,565],{},"How long do we have to answer a request for information, and what happens if we don't?",[29,567,568],{},"Can we answer requests for information through the API?",[29,570,571],{},"How do you handle end customers of our customers?",[29,573,574],{},"Which business activities do you prohibit, and which need extra disclosure?",[11,576,577,578,582],{},"Write the answers into your vendor file. ",[154,579,581],{"href":580},"\u002Fresources\u002Fmore\u002Fstablecoin-payments-provider-due-diligence","Stablecoin payments provider due diligence"," has the wider set of 30 questions.",[21,584,586],{"id":585},"how-does-blindpay-split-compliance-with-you","How does BlindPay split compliance with you?",[11,588,589],{},"BlindPay handles the compliance layer: you collect the data, and BlindPay verifies it. Every payment flows through a verified customer.",[26,591,592,598,604,610,616,627,641],{},[29,593,594,597],{},[176,595,596],{},"KYC and KYB levels."," KYC Standard for individuals is automated and takes about 60 seconds. KYC Enhanced is required for individuals from high-risk countries and is reviewed manually, as is KYB Standard for businesses, in 3 hours to 1 business day.",[29,599,600,603],{},[176,601,602],{},"Every customer is registered."," Every customer on your platform must be registered as a customer in BlindPay. If one of your customers is itself a money transmitter, its end customers must be registered too.",[29,605,606,609],{},[176,607,608],{},"Terms of service."," Each customer accepts BlindPay's terms before onboarding, and again when the terms change.",[29,611,612,615],{},[176,613,614],{},"Limits per tier."," Payins and payouts have separate limits. Per transaction, KYC Standard starts at $10,000, KYB Standard at $30,000, and KYC Enhanced at $50,000, with a limit-increase flow backed by documents.",[29,617,618,621,622,626],{},[176,619,620],{},"Transaction monitoring with on-hold review."," BlindPay's KYT flags suspicious payins and payouts and puts them ",[623,624,625],"code",{},"on_hold",". The compliance team reviews each one and may send a request for information. If it isn't answered within 24 hours, the payment may be refunded to the sender.",[29,628,629,632,633,636,637,640],{},[176,630,631],{},"Requests for information through the API."," When a customer's review needs more data, a ",[623,634,635],{},"customer.update"," webhook signals ",[623,638,639],{},"compliance_request",", and you fetch and answer the request with the RFI endpoints.",[29,642,643,646],{},[176,644,645],{},"Nesting rule."," You can't move money through your account for parties BlindPay can't see. A business rejected for nesting can onboard as its own BlindPay instance, at no extra cost, and register its customers there.",[11,648,649,650,654,655,659,660,192],{},"The details are in the docs for ",[154,651,653],{"href":652},"\u002Fdocs\u002Fkb\u002Fkyc","KYC requirements",", ",[154,656,658],{"href":657},"\u002Fdocs\u002Fkb\u002Fon-hold-transactions","on-hold transactions",", and ",[154,661,663],{"href":662},"\u002Fdocs\u002Fkb\u002Fnested-payments","nested payments",[11,665,666,669,670,673,674,192],{},[176,667,668],{},"When BlindPay is the right fit:"," you want compliance handled inside the API, with KYC, KYB, monitoring, and holds visible as statuses and webhooks you can build screens around. ",[176,671,672],{},"When it isn't:"," you want to run your own identity verification and only buy liquidity, or your business falls under BlindPay's ",[154,675,677],{"href":676},"\u002Fdocs\u002Fkb\u002Fprohibited-activities","prohibited activities",[21,679,681],{"id":680},"what-to-do-next","What to do next",[11,683,684],{},"Draw your flow of funds on one page: where the payer's money goes, who holds it at each step, and whose wallet the stablecoins reach. Mark who verifies each party. Take that page to your provider and your lawyer. Most compliance surprises show up as a box on that page that nobody owns.",[11,686,687,688,692,693,697],{},"If you're still choosing a provider, ",[154,689,691],{"href":690},"\u002Fresources\u002Fmore\u002Fbusiness-vs-consumer-crypto-on-ramps","business vs consumer crypto on-ramps"," explains why business on-ramps verify more than consumer ones. ",[154,694,696],{"href":695},"\u002Fresources\u002Fmore\u002Fhow-to-integrate-a-crypto-on-ramp-api","Integrating a crypto on-ramp API"," shows where the KYC, hold, and request-for-information statuses appear in code.",[11,699,700],{},[17,701,702],{},"This article is general information, not legal, tax, or financial advice. Regulations change, and obligations depend on your jurisdiction and contracts; confirm with qualified counsel.",{"title":704,"searchDepth":705,"depth":705,"links":706},"",2,[707,708,709,710,711,712,713,714,715,716,717],{"id":23,"depth":705,"text":24},{"id":46,"depth":705,"text":47},{"id":166,"depth":705,"text":167},{"id":243,"depth":705,"text":244},{"id":368,"depth":705,"text":369},{"id":395,"depth":705,"text":396},{"id":428,"depth":705,"text":429},{"id":481,"depth":705,"text":482},{"id":535,"depth":705,"text":536},{"id":585,"depth":705,"text":586},{"id":680,"depth":705,"text":681},"compliance","2026-09-26","An on-ramp API splits compliance between the provider and you. Who runs KYC, KYB, KYT, sanctions, and the travel rule, and what stays on your side.","md",[723,726,729,732,735,738],{"q":724,"a":725},"Does a crypto on-ramp need a license?","Generally yes, but which one depends on the jurisdiction. In the US, a business that accepts fiat and transmits virtual currency is usually a money transmitter under FinCEN's rules, which means registering as a money services business and holding state licenses or an exemption. The EU requires authorization as a crypto-asset service provider under MiCA, and Brazil licenses virtual asset service providers through its central bank. Ask a lawyer for your specific setup.",{"q":727,"a":728},"If I use an on-ramp API, do I still need to do KYC?","You usually collect the KYC data and the provider verifies it. The provider runs the identity checks, sanctions screening, and transaction monitoring because it's the regulated party moving the money. You stay responsible for collecting accurate information, keeping it up to date, and not letting unverified people pay through your account.",{"q":730,"a":731},"What is KYT in a crypto on-ramp?","KYT, or know your transaction, is ongoing monitoring of each payment after onboarding. It looks at amounts, frequency, counterparties, and patterns to flag activity that doesn't fit the customer's profile. A flagged on-ramp payment is usually held for a manual review instead of being rejected outright.",{"q":733,"a":734},"What is the difference between KYC and KYB?","KYC verifies an individual: identity document, date of birth, address, and a sanctions check. KYB verifies a business: registration documents, the beneficial owners who own or control it, its directors, and its line of business. KYB usually takes a manual review, while standard KYC can be automated.",{"q":736,"a":737},"What happens if my customer's on-ramp payment is flagged?","It's put on hold while the provider's compliance team reviews it. If they can't clear it internally, they'll ask you for information such as the purpose of the payment and the relationship between the payer and your customer. Answer quickly: on BlindPay, an unanswered request after 24 hours may end in a refund to the sender.",{"q":739,"a":740},"Can a platform use one on-ramp account for all of its customers?","Not if those customers' money moves through it unseen. Regulated providers need to see every party whose funds they move. A platform that pools many customers' deposits under its own account without registering them is nesting, which most providers prohibit. Register each customer with the provider instead.",false,{"author":743},"BlindPay Team",true,"\u002Fresources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what","---\ntitle: \"Who owns compliance when you integrate a crypto on-ramp API? KYC, KYB, KYT, and holds\"\nseoTitle: \"Crypto on-ramp compliance: who owns KYC, KYB, and KYT\"\ndescription: \"An on-ramp API splits compliance between the provider and you. Who runs KYC, KYB, KYT, sanctions, and the travel rule, and what stays on your side.\"\ndate: \"2026-09-26\"\nupdated: \"2026-09-26\"\nauthor: \"BlindPay Team\"\ncategory: \"compliance\"\nfaq:\n  - q: \"Does a crypto on-ramp need a license?\"\n    a: \"Generally yes, but which one depends on the jurisdiction. In the US, a business that accepts fiat and transmits virtual currency is usually a money transmitter under FinCEN's rules, which means registering as a money services business and holding state licenses or an exemption. The EU requires authorization as a crypto-asset service provider under MiCA, and Brazil licenses virtual asset service providers through its central bank. Ask a lawyer for your specific setup.\"\n  - q: \"If I use an on-ramp API, do I still need to do KYC?\"\n    a: \"You usually collect the KYC data and the provider verifies it. The provider runs the identity checks, sanctions screening, and transaction monitoring because it's the regulated party moving the money. You stay responsible for collecting accurate information, keeping it up to date, and not letting unverified people pay through your account.\"\n  - q: \"What is KYT in a crypto on-ramp?\"\n    a: \"KYT, or know your transaction, is ongoing monitoring of each payment after onboarding. It looks at amounts, frequency, counterparties, and patterns to flag activity that doesn't fit the customer's profile. A flagged on-ramp payment is usually held for a manual review instead of being rejected outright.\"\n  - q: \"What is the difference between KYC and KYB?\"\n    a: \"KYC verifies an individual: identity document, date of birth, address, and a sanctions check. KYB verifies a business: registration documents, the beneficial owners who own or control it, its directors, and its line of business. KYB usually takes a manual review, while standard KYC can be automated.\"\n  - q: \"What happens if my customer's on-ramp payment is flagged?\"\n    a: \"It's put on hold while the provider's compliance team reviews it. If they can't clear it internally, they'll ask you for information such as the purpose of the payment and the relationship between the payer and your customer. Answer quickly: on BlindPay, an unanswered request after 24 hours may end in a refund to the sender.\"\n  - q: \"Can a platform use one on-ramp account for all of its customers?\"\n    a: \"Not if those customers' money moves through it unseen. Regulated providers need to see every party whose funds they move. A platform that pools many customers' deposits under its own account without registering them is nesting, which most providers prohibit. Register each customer with the provider instead.\"\n---\n\nA crypto on-ramp is generally regulated as a money transmitter or a virtual asset service provider, so it must run KYC, AML, sanctions screening, and transaction monitoring on everyone who pays in. When you integrate one through an API, the provider runs those checks. You still own the data you collect, the customers you bring, and your own licensing questions.\n\n*This article is general information, not legal advice. Compliance obligations depend on your jurisdiction, your business model, and your contract with the provider. Talk to counsel before you rely on any of it.*\n\n## Key takeaways\n\n- The provider is the regulated party for the conversion. It verifies identities, screens sanctions, monitors transactions, and files reports.\n- You collect the data, keep it accurate, and make sure only verified customers pay through your account.\n- Every party whose money moves needs to be visible to the provider. Pooling unregistered end customers under your account is nesting.\n- Holds are part of the system. Plan who answers a request for information, and how fast.\n- Whether you need your own license depends on whether you ever take possession of the money. That's a question for a lawyer, not a blog post.\n\n## What compliance checks does a crypto on-ramp run?\n\nSeven checks, each with a different job.\n\n| Term | What it means | When it runs |\n| --- | --- | --- |\n| KYC (know your customer) | Verifying an individual's identity | Onboarding, and again when data changes |\n| KYB (know your business) | Verifying a company, its owners, and its directors | Onboarding, and on periodic review |\n| AML (anti-money laundering) | The program of policies, controls, and reporting that prevents laundering | Always |\n| CFT (countering the financing of terrorism) | The same program, aimed at terrorist financing | Always |\n| KYT (know your transaction) | Monitoring each payment for unusual patterns | Every transaction |\n| Sanctions screening | Checking people, companies, and wallet addresses against lists like OFAC's SDN list | Onboarding and every transaction |\n| Travel rule | Passing originator and beneficiary data with a transfer between providers | Transfers above the local threshold |\n\nKYC and KYB answer \"who is this?\". KYT answers \"does this payment make sense for them?\". [What is KYB](\u002Fresources\u002Fmore\u002Fwhat-is-kyb) goes deeper on business checks, and [the travel rule for off-ramps](\u002Fresources\u002Fmore\u002Ftravel-rule-stablecoin-off-ramps) covers thresholds by country.\n\n## What do regulators expect from on-ramps?\n\nFour primary sources set the frame. Read them directly; summaries, including this one, drop detail.\n\n- **FinCEN (US).** The [2019 guidance on convertible virtual currency](https:\u002F\u002Fwww.fincen.gov\u002Fresources\u002Fstatutes-regulations\u002Fguidance\u002Fapplication-fincens-regulations-certain-business-models) treats businesses that accept and transmit virtual currency as money transmitters, with registration, AML program, recordkeeping, and reporting duties. You can check a provider's registration in the [MSB registrant search](https:\u002F\u002Fwww.fincen.gov\u002Fmsb-registrant-search).\n- **OFAC (US).** The [sanctions compliance guidance for the virtual currency industry](https:\u002F\u002Fofac.treasury.gov\u002Fmedia\u002F913571\u002Fdownload?inline) expects screening of customers and wallet addresses, and a risk-based sanctions program.\n- **FATF (global).** The [updated guidance on virtual assets and VASPs](https:\u002F\u002Fwww.fatf-gafi.org\u002Fen\u002Fpublications\u002FFatfrecommendations\u002FGuidance-rba-virtual-assets-2021.html) sets the standard most countries copy: customer due diligence, monitoring, and the travel rule.\n- **EU.** [MiCA](https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2023\u002F1114\u002Foj) requires crypto-asset service providers to be authorized, and the [Transfer of Funds Regulation](https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2023\u002F1113\u002Foj) applies the travel rule to crypto transfers with no minimum amount.\n\nThe pattern is the same everywhere: know who's paying, watch what they do, screen against sanctions, keep records, and report what looks wrong. [What is a VASP](\u002Fresources\u002Fmore\u002Fwhat-is-a-vasp) explains how the FATF definition maps onto local licenses.\n\n## Who is responsible for what when you integrate an on-ramp API?\n\nThe provider runs the regulated checks. You run your business honestly on top of them. The split below is typical; your contract and your jurisdiction decide the real one.\n\n| Task | On-ramp provider | Your company |\n| --- | --- | --- |\n| Collect identity and business data | Defines what's required | Collects it from your users, accurately |\n| Verify identity (KYC) and businesses (KYB) | Runs the checks and decides | Passes the data and the documents through |\n| Sanctions screening | Screens customers, payers, and wallets | Doesn't onboard people you know are sanctioned |\n| Transaction monitoring (KYT) | Monitors and holds suspicious payments | Answers requests for information |\n| Suspicious activity reports | Files them with its regulator | Reports concerns through the provider's channel |\n| Travel rule data | Exchanges it with other providers | Supplies accurate sender and recipient details |\n| Terms of service | Publishes them | Makes sure each customer accepts them |\n| Your own licensing | Not its responsibility | Yours to assess with counsel |\n| End customers behind your customers | Requires them to be registered | Registers them; doesn't pool them |\n\nTwo rows trip people up. The first is data quality: the provider verifies what you send, so a sloppy onboarding form becomes a compliance problem downstream. The second is the last row, covered next.\n\n## What is nesting, and why do on-ramps prohibit it?\n\nNesting is moving money for a party the provider can't see. If one customer's account carries deposits that economically belong to many other businesses or people, and the provider never onboarded them, the structure is nested.\n\nSigns of nesting:\n\n- Funds in the account belong to someone other than the onboarded customer.\n- Invoices or contracts name a different entity than the account holder.\n- One account collects for several underlying businesses.\n- Each sub-account or virtual account represents a different third party's money.\n\nRegulators treat this as a way to hide who's really behind a payment, which is why providers prohibit it. The fix is visibility: register each end customer with the provider, or have the business that serves them onboard as its own direct customer.\n\n## Do you need your own license if you use an on-ramp API?\n\nMaybe. It depends on what your product does with the money, and only a lawyer who has read your flow of funds can answer it.\n\nThe questions that usually decide it:\n\n1. Does money ever land in an account you control, even for a moment?\n2. Do you hold stablecoins or fiat on behalf of users?\n3. Do you set the exchange rate, or does the provider?\n4. Are your users individuals, businesses, or both, and in which countries?\n\nA product that only passes data to a licensed provider, with funds moving straight from the payer to the provider and stablecoins straight to the user's own wallet, sits in a different place than one that collects funds first. [Do merchants need a license to accept stablecoins](\u002Fresources\u002Fmore\u002Fdo-merchants-need-a-license-to-accept-stablecoins) walks through a related version of the question.\n\n## What does a good on-ramp compliance flow look like?\n\nSix stages, in order:\n\n1. **Onboarding.** Collect the data, accept the terms, run KYC or KYB.\n2. **Risk scoring.** Higher-risk countries, business types, or structures get enhanced review.\n3. **Limits.** Each verification tier gets per-transaction, daily, and monthly limits.\n4. **Monitoring.** Every payin is screened and scored as it happens.\n5. **Holds and requests for information.** Flagged payments pause for a human, who may ask you questions.\n6. **Decision.** Release, refund, or escalate, and keep the record.\n\nThe stages after onboarding are where integrations break. A product that handles approval but has no screen for \"in review\" will generate support tickets on day one. [Real-time transaction monitoring](\u002Fresources\u002Fmore\u002Freal-time-transaction-monitoring-stablecoin-payments) shows a flagged payment from start to finish.\n\n## How should you think about compliance across countries?\n\nDon't build a table of rules per country. It goes stale. Build a checklist of what varies, and ask the provider how it handles each one in your markets:\n\n- **Licensing regime.** Money transmitter, VASP, payment institution, or something new, like Brazil's VASP rules covered in [PSAV Brazil explained](\u002Fresources\u002Fmore\u002Fpsav-brazil-explained).\n- **Identity documents and tax IDs.** CPF and CNPJ in Brazil, CUIT and CUIL in Argentina, NIT in Colombia.\n- **Enhanced review.** Which countries trigger manual checks.\n- **Travel rule thresholds.** These differ, and some markets apply the rule with no minimum.\n- **Data protection.** Where identity data is stored and who processes it.\n- **Stablecoin rules.** Some markets regulate the token itself, like the US under the [GENIUS Act](\u002Fresources\u002Fmore\u002Fgenius-act-for-businesses) and the EU under MiCA.\n\n## What 12 questions should you ask a provider about compliance?\n\n1. Which licenses or registrations do you hold, in which entities, and where can I verify them?\n2. Who verifies identity: you, or a vendor you rely on?\n3. Which fields and documents are required for KYC and for KYB?\n4. How long do automated and manual reviews take?\n5. Which countries trigger enhanced review, and which can't onboard at all?\n6. What are the default limits per tier, and how do customers raise them?\n7. Do you screen wallet addresses as well as people?\n8. How are flagged payments held, and how will you contact us?\n9. How long do we have to answer a request for information, and what happens if we don't?\n10. Can we answer requests for information through the API?\n11. How do you handle end customers of our customers?\n12. Which business activities do you prohibit, and which need extra disclosure?\n\nWrite the answers into your vendor file. [Stablecoin payments provider due diligence](\u002Fresources\u002Fmore\u002Fstablecoin-payments-provider-due-diligence) has the wider set of 30 questions.\n\n## How does BlindPay split compliance with you?\n\nBlindPay handles the compliance layer: you collect the data, and BlindPay verifies it. Every payment flows through a verified customer.\n\n- **KYC and KYB levels.** KYC Standard for individuals is automated and takes about 60 seconds. KYC Enhanced is required for individuals from high-risk countries and is reviewed manually, as is KYB Standard for businesses, in 3 hours to 1 business day.\n- **Every customer is registered.** Every customer on your platform must be registered as a customer in BlindPay. If one of your customers is itself a money transmitter, its end customers must be registered too.\n- **Terms of service.** Each customer accepts BlindPay's terms before onboarding, and again when the terms change.\n- **Limits per tier.** Payins and payouts have separate limits. Per transaction, KYC Standard starts at $10,000, KYB Standard at $30,000, and KYC Enhanced at $50,000, with a limit-increase flow backed by documents.\n- **Transaction monitoring with on-hold review.** BlindPay's KYT flags suspicious payins and payouts and puts them `on_hold`. The compliance team reviews each one and may send a request for information. If it isn't answered within 24 hours, the payment may be refunded to the sender.\n- **Requests for information through the API.** When a customer's review needs more data, a `customer.update` webhook signals `compliance_request`, and you fetch and answer the request with the RFI endpoints.\n- **Nesting rule.** You can't move money through your account for parties BlindPay can't see. A business rejected for nesting can onboard as its own BlindPay instance, at no extra cost, and register its customers there.\n\nThe details are in the docs for [KYC requirements](\u002Fdocs\u002Fkb\u002Fkyc), [on-hold transactions](\u002Fdocs\u002Fkb\u002Fon-hold-transactions), and [nested payments](\u002Fdocs\u002Fkb\u002Fnested-payments).\n\n**When BlindPay is the right fit:** you want compliance handled inside the API, with KYC, KYB, monitoring, and holds visible as statuses and webhooks you can build screens around. **When it isn't:** you want to run your own identity verification and only buy liquidity, or your business falls under BlindPay's [prohibited activities](\u002Fdocs\u002Fkb\u002Fprohibited-activities).\n\n## What to do next\n\nDraw your flow of funds on one page: where the payer's money goes, who holds it at each step, and whose wallet the stablecoins reach. Mark who verifies each party. Take that page to your provider and your lawyer. Most compliance surprises show up as a box on that page that nobody owns.\n\nIf you're still choosing a provider, [business vs consumer crypto on-ramps](\u002Fresources\u002Fmore\u002Fbusiness-vs-consumer-crypto-on-ramps) explains why business on-ramps verify more than consumer ones. [Integrating a crypto on-ramp API](\u002Fresources\u002Fmore\u002Fhow-to-integrate-a-crypto-on-ramp-api) shows where the KYC, hold, and request-for-information statuses appear in code.\n\n*This article is general information, not legal, tax, or financial advice. Regulations change, and obligations depend on your jurisdiction and contracts; confirm with qualified counsel.*\n",{"title":5,"description":720},"Crypto on-ramp compliance: who owns KYC, KYB, and KYT","resources\u002Fmore\u002Fcrypto-on-ramp-compliance-who-owns-what","SykpknkRIBFxwsPQXNX6AgToJfNppAJm47fsE3NVml0",[752,756,760,764,768,771,775,779,783,786,789,793,797,801,804,808,812,815,818,822,825,826],{"path":753,"title":754,"description":755},"\u002Fresources\u002Fmore\u002Fare-stablecoin-payments-reversible","Are stablecoin payments reversible? Finality, custody, and fraud explained","Stablecoin transfers settle final in minutes and cannot be reversed. That finality proves custody at every step, but it also opens a fraud gap on the fiat side of the payment.",{"path":757,"title":758,"description":759},"\u002Fresources\u002Fmore\u002Fautomated-kyc-kyb-vs-manual-onboarding","Automated KYC\u002FKYB vs. manual onboarding: what actually changes","A side-by-side comparison of automated and manual KYC\u002FKYB for fintechs: onboarding time, false-positive rates, cost per verification, scaling across jurisdictions, and audit-trail quality, plus the cases where a human reviewer is still required.",{"path":761,"title":762,"description":763},"\u002Fresources\u002Fmore\u002Fcompliance-agents-cross-border-stablecoin-payments","Compliance agents for cross-border stablecoin payments: a global regulatory guide","How compliance agents apply FinCEN, MiCA, FCA, MAS, and Banco Central do Brasil rules to cross-border stablecoin payments: jurisdiction table, the FATF Travel Rule, multi-list sanctions screening, the four components of a compliant program, and questions to ask a compliance provider.",{"path":765,"title":766,"description":767},"\u002Fresources\u002Fmore\u002Fcrypto-wallet-compliance-checklist","Crypto wallet compliance checklist: KYC, KYT, and Travel Rule","The compliance that comes with crypto wallets and stablecoin payments: KYC and KYB, KYT, the Travel Rule, address screening, MSB rules, and 15 checks.",{"path":423,"title":769,"description":770},"Do merchants need a license to accept stablecoin payments? KYC, KYB, and compliance explained","Usually no: the license sits with the provider that moves the funds. What merchants still owe on KYB, sanctions, tax, and records in the US, EU, Brazil.",{"path":772,"title":773,"description":774},"\u002Fresources\u002Fmore\u002Fhow-to-automate-kyc-kyb-stablecoin-payments","How to automate KYC and KYB for stablecoin payments","A developer guide to automated KYC and KYB for stablecoin payment flows: how verification runs inside a payment API, step-by-step workflows for individuals and businesses, jurisdiction requirements for the US, EU, UK, Singapore, and Brazil, and what to check before settlement.",{"path":776,"title":777,"description":778},"\u002Fresources\u002Fmore\u002Fhow-to-choose-automated-risk-monitoring-vendor","How to choose an automated risk monitoring vendor for a fintech startup","A buyer's guide to automated risk monitoring vendors for early-stage fintechs: the five criteria that matter (regulatory coverage, integration effort, false-positive rate, pricing model, audit output), the question to ask a vendor on each, a checklist table, and what it costs.",{"path":780,"title":781,"description":782},"\u002Fresources\u002Fmore\u002Fmica-stablecoin-rules-explained","MiCA stablecoin rules explained for payment companies","What MiCA means if your business uses stablecoins in the EU: EMTs vs ARTs, issuer requirements, why USDC is compliant and USDT was delisted, and a practical checklist.",{"path":496,"title":784,"description":785},"PSAV in Brazil: the Central Bank's virtual asset license explained","PSAV is Brazil's authorization for virtual asset service providers, created by BCB Resolutions 519, 520, and 521 under Law 14.478\u002F2022. What it requires and who needs it.",{"path":476,"title":787,"description":788},"Real-time transaction monitoring for cross-border stablecoin payments","Why stablecoin cross-border flows need different monitoring than wires: the signals that get scored (wallet address risk, velocity, corridor risk, on\u002Foff-ramp counterparties), real-time vs. batch monitoring, and a worked example of a flagged pattern from alert to decision.",{"path":790,"title":791,"description":792},"\u002Fresources\u002Fmore\u002Fstablecoin-card-issuing-compliance","Stablecoin card issuing compliance: KYC, KYB, and regulatory coverage explained","What compliance stablecoin card issuing requires: KYC vs. KYB, who is responsible for what, how rules differ in the US, EU, UK, and Latin America, and ongoing monitoring.",{"path":794,"title":795,"description":796},"\u002Fresources\u002Fmore\u002Fstablecoin-off-ramp-limits","Stablecoin off-ramp limits: per-transaction, daily, and monthly caps explained","Why off-ramps cap how much you can convert per transaction, day, and month, how the caps map to KYC and KYB tiers, and the documents that raise them.",{"path":798,"title":799,"description":800},"\u002Fresources\u002Fmore\u002Fstablecoin-regulation-tracker-2026","Stablecoin regulation in 2026: MiCA, the GENIUS Act, Brazil, and Japan","Where stablecoin regulation stands in 2026: MiCA in the EU, the GENIUS Act in the US, Brazil's VASP regime, and Japan's issuer rules, compared for payment businesses.",{"path":530,"title":802,"description":803},"The GENIUS Act explained for businesses that use stablecoins","What the GENIUS Act means if your business sends, receives, or holds stablecoins: who it regulates, the dates that matter, and what to do before 2027.",{"path":805,"title":806,"description":807},"\u002Fresources\u002Fmore\u002Fvirtual-account-requirements-kyc-kyb","Virtual account requirements: KYC, KYB, and what the bank reviews before it says yes","What you need to open a virtual account: KYC or KYB, the extra fields and source of funds documents the bank reviews, who owns each step, and timelines.",{"path":809,"title":810,"description":811},"\u002Fresources\u002Fmore\u002Fwhat-are-compliance-agents-in-fintech","What are compliance agents in fintech? How they work and what they do for payments","Compliance agents are autonomous software components that run KYC, KYB, sanctions screening, and transaction monitoring inside a payment flow, then document every decision. How they work, what they do for payments, how they differ from traditional compliance software, and how BlindPay embeds them in its API.",{"path":156,"title":813,"description":814},"What is KYB? Know Your Business verification explained","KYB verifies a company's legal existence, ownership, and control before it can transact. What it checks, who counts as a beneficial owner, and how it differs from KYC.",{"path":238,"title":816,"description":817},"What is a VASP? Virtual asset service provider explained","A VASP is any business that exchanges, transfers, or custodies virtual assets like stablecoins for customers. FATF's definition and what it requires in practice.",{"path":819,"title":820,"description":821},"\u002Fresources\u002Fmore\u002Fwhat-is-automated-risk-monitoring-fintech","What is automated risk monitoring in fintech?","A reference explainer on automated risk monitoring for fintechs: the four components (KYC\u002FKYB, transaction monitoring, sanctions and watchlist screening, compliance automation), what each one flags, a manual vs. automated comparison, and what FinCEN, FATF, and OFAC actually require.",{"path":161,"title":823,"description":824},"What is the travel rule for stablecoin off-ramps? Thresholds, data, and failed checks","The travel rule makes off-ramps pass sender and receiver data with transfers. Thresholds by country, required data, and what happens when checks fail.",{"path":745,"title":5,"description":720},{"path":827,"title":828,"description":829},"\u002Fresources\u002Fmore\u002Fsource-of-funds-crypto-off-ramps","Why do crypto off-ramps ask for source of funds? Documents, triggers, and on-chain proof","Why off-ramps ask where your stablecoins came from, how source of funds differs from source of wealth, what triggers a request, and which documents pass.",1790867716163]