Crypto wallet compliance checklist: KYC, KYT, and Travel Rule

The compliance that comes with crypto wallets and stablecoin payments: KYC and KYB, KYT, the Travel Rule, address screening, MSB rules, and 15 checks.

Adding crypto wallets or stablecoin payments to a product brings five compliance areas: verifying users (KYC and KYB), monitoring transactions (KYT), passing sender and recipient data (the Travel Rule), screening people and wallet addresses against sanctions lists, and deciding whether your company needs money transmitter registration. Your custody model decides which of these land on you.

This article is general information, not legal advice. Rules differ by country and change often, so confirm your obligations with counsel before launch.

The wallet changes the compliance picture in one specific way: it adds a new identifier, the wallet address, that carries its own risk history, can belong to someone other than your customer, and may sit outside any regulated provider. Most items below come back to that. If you're still choosing a custody model, read custodial vs non-custodial vs MPC wallets first.

What compliance do you need for a crypto wallet integration?

A wallet integration needs identity checks on users, monitoring of transactions and addresses, Travel Rule data exchange, sanctions screening, and a clear answer on licensing. The table shows when each one runs and what the wallet adds to it.

AreaWhat it checksWhen it runsWhat the wallet adds
KYC and KYBWho the customer isOnboarding, then periodic and trigger-based reviewsEach wallet has to map to a verified customer
KYTWhat the customer doesEvery transactionAddress risk travels with funds from counterparties
Travel RuleWho sends and who receivesTransfers between providersSelf-hosted addresses have no provider on the other side
Sanctions screeningParties and addresses against sanctions listsOnboarding, each transfer, each list updateAddresses can be sanctioned, not only people
LicensingWhether your company transmits or holds valueBefore launchCustody model drives the answer

KYC and KYB: who must be verified, when, and with what data?

Everyone whose money moves through your product should be verified before it moves. KYC, know your customer, verifies individuals. KYB, know your business, verifies companies and the people who own and control them.

For individuals, the core identity data is name, date of birth, address, and an identification number, checked against documents or trusted databases. For businesses, it's the legal entity, its registration and address, and its beneficial owners. In the US, FinCEN's Customer Due Diligence rule covers anyone owning 25 percent or more, plus one person who controls or manages the company. What is KYB walks through the full list.

The wallet-specific rule: every wallet address in your system should belong to a verified customer, and you should be able to prove it. On EVM chains the cleanest proof is a signed message from the wallet at registration, which the wallet integration tutorial shows step by step. Re-run the check whenever a customer adds a wallet, not only at signup. How to automate KYC and KYB covers the verification flow itself.

KYT (know your transaction): what is transaction monitoring and what does it flag?

KYT, know your transaction, is transaction monitoring for crypto. It scores each transfer and the wallet addresses on both sides for risk, before funds settle where possible and continuously afterward. A verified customer can still receive funds from a sanctioned address, which is exactly what KYT exists to catch.

KYT flags two kinds of risk. On-chain exposure comes from blockchain analytics: an address that received funds, directly or through a few hops, from a sanctioned entity, a mixer, a darknet market, a scam, or a hack. Behavioral patterns come from rules on your own data:

  • Velocity spikes: many transfers in a short window, well above the customer's normal activity.
  • Structuring: repeated amounts just under a reporting threshold, such as the USD 3,000 US Travel Rule threshold.
  • Pass-through: funds received and sent onward within minutes.
  • Large crypto inflows followed immediately by conversion to fiat.
  • Several unrelated wallets paying the same bank account.
  • Activity that doesn't match the customer's declared business.

Real-time transaction monitoring for stablecoin payments shows how a flagged pattern moves from alert to decision.

What is the Travel Rule and when does it apply to stablecoin transfers?

The Travel Rule requires providers that transfer virtual assets to send the originator's and beneficiary's information along with the transfer, and requires the receiving provider to collect and check it. It applies to stablecoin transfers between regulated providers, with thresholds that vary by country.

The rule comes from FATF Recommendation 16, which FATF extended to virtual asset service providers in 2019. FATF adopted a revised Recommendation 16 in June 2025, retitled "payment transparency," with implementation expected by the end of 2030. National rules implement it differently:

  • United States: the recordkeeping and travel rule in 31 CFR 1010.410(f) applies to transmittals of USD 3,000 or more.
  • European Union: the Transfer of Funds Regulation, Regulation (EU) 2023/1113, has applied to crypto-asset transfers since December 30, 2024, with no minimum amount.

Self-hosted wallets are where wallet integrations get specific. A self-hosted wallet, one the user controls without a provider, has no counterparty to receive Travel Rule data. The EU's answer is that for a transfer above EUR 1,000 to or from a self-hosted address, the crypto-asset service provider must verify that the address is owned or controlled by its own customer. Wallet ownership proof stops being a nice-to-have and becomes part of the rule. The travel rule for stablecoin off-ramps has the full threshold table and what happens when a check fails.

Sanctions screening and wallet address screening

Screen people against sanctions lists, and screen wallet addresses against both the lists and blockchain analytics. A wallet address can be sanctioned in its own right, and a clean person can hold a tainted address.

OFAC may add digital currency addresses to entries on the Specially Designated Nationals (SDN) List, and says plainly that those listings may not be complete. So checking addresses against the SDN List alone isn't enough. Blockchain analytics tools trace an address's history and score its exposure to sanctioned entities that were never listed by address.

Screen at three moments:

  1. When a wallet is registered, before it can receive or fund anything.
  2. Before each transfer, on both the customer's address and the counterparty's.
  3. When lists update. OFAC, the EU, the UN, and the UK each publish on their own schedules, so rescreen existing customers and addresses against every update.

On a true match, block or reject the transfer, don't tell the customer why, and report as the relevant sanctions authority requires. Document every decision, including the clean ones.

Do you need a money transmitter or MSB registration?

If your company accepts and transmits value for others, or holds it with independent control, you likely need registration. In the US that means registering with FinCEN as a money services business (MSB) and, in most states, holding a money transmitter license.

FinCEN's 2019 guidance on convertible virtual currency (FIN-2019-G001, May 9, 2019) decides wallet cases on four facts: who owns the value, where it is stored, whether the owner interacts with the network directly, and whether the intermediary has total independent control over it. Hosted wallet providers are money transmitters. A person using an unhosted wallet to buy goods or services for themselves is not. What is a VASP covers the international version of the same question.

BlindPay is registered with FinCEN as a money services business, and its registrations are published on the licenses page. Building on a registered provider whose payouts are non-custodial, where your company never holds or transmits the funds itself, can change your own exposure. It doesn't settle the question. Your flows, your custody model, and your states decide it, so confirm with counsel. Do merchants need a license to accept stablecoins covers the merchant case.

How does compliance differ by region?

The core areas are the same everywhere. Thresholds, licenses, and supervisors differ. Sources are dated below; treat this as a snapshot as of September 2026 and check the stablecoin regulation tracker for updates.

RegionMain frameworkWallet-relevant pointsSource
United StatesBank Secrecy Act, enforced by FinCEN; state money transmitter laws; the GENIUS Act for payment stablecoin issuersHosted wallet providers are money transmitters; Travel Rule at USD 3,000FinCEN FIN-2019-G001 (May 2019); GENIUS Act (signed July 18, 2025)
European UnionMiCA for crypto-asset service providers; the Transfer of Funds RegulationCustody needs authorization; Travel Rule with no threshold; self-hosted checks above EUR 1,000MiCA and TFR (2023, applying since December 30, 2024)
BrazilLaw 14.478/2022; Banco Central do Brasil Resolutions 519, 520, and 521Virtual asset service providers need Central Bank authorizationBCB resolutions (published November 10, 2025, effective February 2, 2026)
MexicoThe 2018 Fintech Law, with Banco de México and the CNBV as supervisorsBanco de México limits how financial institutions may deal in virtual assetsFintech Law (2018)

MiCA stablecoin rules explained and PSAV in Brazil go deeper on the EU and Brazil.

A 15-item pre-launch compliance checklist

Run this list before the first real transfer. Each item should have an owner and a written answer.

  1. Counsel has reviewed your custody model and flows, and confirmed which registrations or licenses you need.
  2. Every customer passes KYC or KYB before any quote, deposit, or payout.
  3. Business customers have beneficial owners and a control person on file.
  4. Every wallet address maps to exactly one verified customer.
  5. EVM wallets prove control with a signed message at registration.
  6. Addresses submitted directly come from your wallet provider's API, not from user input.
  7. Customers and beneficial owners are screened against OFAC, EU, UN, and UK sanctions lists at onboarding.
  8. Wallet addresses are screened against sanctions lists and blockchain analytics at registration.
  9. Counterparty addresses are screened before each transfer.
  10. Customers and addresses are rescreened when sanctions lists update.
  11. KYT rules cover velocity, structuring, pass-through, and fast crypto-to-fiat conversion.
  12. Travel Rule data is collected for transfers at or above each jurisdiction's threshold.
  13. Transfers to and from self-hosted wallets have an ownership check where the rules require one.
  14. Alerts have a documented review process, with named people who can decide on suspicious activity reports.
  15. Records of verification, screening, alerts, and decisions are retained for the required period.

Which compliance tasks can be automated and which cannot?

Automate the checks and keep people on the decisions. Screening, scoring, and data collection run well as software. Judgment calls on matches, high-risk customers, and reports need a trained person.

TaskAutomate?Notes
Document and selfie verificationYesRoute unclear results to manual review
Business registry and ownership collectionMostlyComplex ownership structures need a person
Sanctions and PEP screeningYesA person reviews every potential match
Wallet address screeningYesAnalytics scores, with thresholds you set
KYT scoringYesAlerts go to a review queue
Travel Rule data exchangeYesCounterparty provider due diligence is manual
Enhanced due diligenceNoSource of funds and business model reviews
Suspicious activity report decisionsNoAlways a documented human decision
Licensing and policyNoCounsel and your compliance officer

BlindPay automates the verification side for its customers: Standard KYC usually returns a decision in about 60 seconds, with manual review when needed, and customers are screened at onboarding and on an ongoing basis. Transfers expose a transaction monitoring step with a blockchain screening score and a risk score in the API. Automated KYC and KYB vs manual onboarding and what is automated risk monitoring cover how that automation works in practice.

What to do next

Take the 15-item checklist to your first compliance meeting and mark each line as yours, your provider's, or unknown. Every unknown is a question for counsel or for your provider's compliance team, and both should answer in writing.

This article is general information only and is not legal advice.

FAQ