---
title: "Crypto wallet compliance checklist: KYC, KYT, and Travel Rule"
seoTitle: "Crypto wallet compliance checklist: KYC, KYT, Travel Rule"
description: "The compliance that comes with crypto wallets and stablecoin payments: KYC and KYB, KYT, the Travel Rule, address screening, MSB rules, and 15 checks."
date: "2026-09-28"
updated: "2026-09-28"
category: "compliance"
author: "BlindPay Team"
faq:
  - q: "What compliance is required for a crypto wallet integration?"
    a: "Usually five areas: KYC and KYB to verify users, KYT to monitor transactions and wallet addresses, the Travel Rule to pass sender and recipient data between providers, sanctions screening of people and addresses, and a decision on money transmitter or VASP registration. Your custody model decides which of these your company runs and which your provider runs. Confirm your obligations with counsel."
  - q: "Does the Travel Rule apply to self-hosted wallets?"
    a: "Partly. A self-hosted wallet has no provider on the other side to receive Travel Rule data, but rules still reach the provider serving your customer. In the EU, the Transfer of Funds Regulation requires a crypto-asset service provider to verify that a self-hosted address is owned or controlled by its customer for transfers above EUR 1,000. Other jurisdictions set their own approach."
  - q: "What is wallet address screening?"
    a: "Wallet address screening checks a blockchain address against sanctions lists and blockchain analytics before funds move to or from it. OFAC includes some digital currency addresses in SDN List entries, but those listings are not complete, so analytics tools also score an address's exposure to sanctioned entities, mixers, scams, and stolen funds. Screen at registration, before each transfer, and when lists change."
  - q: "What is the difference between KYC and KYT?"
    a: "KYC verifies who a customer is, once at onboarding and again on a schedule or trigger. KYT, know your transaction, watches what the customer does: each transfer's amount, speed, counterparties, and the risk of the wallet addresses involved. A fully verified customer can still send or receive funds that KYT flags, which is why programs need both."
  - q: "Do I need an MSB registration to offer crypto wallets?"
    a: "It depends on whether your company holds or transmits value for others. FinCEN's 2019 guidance treats hosted wallet providers as money transmitters, which register as money services businesses and often need state licenses. Users of unhosted wallets are not. Working with a registered, non-custodial provider can change your exposure, but only counsel can confirm it for your flows."
  - q: "Can crypto wallet compliance be fully automated?"
    a: "Most checks can be automated: document and selfie verification, registry lookups, sanctions and address screening, transaction scoring, and Travel Rule messaging. Decisions can't: reviewing screening matches, enhanced due diligence on high-risk customers, deciding whether to file a suspicious activity report, and licensing strategy. Automation clears the routine cases so people can focus on the rest."
---

Adding crypto wallets or stablecoin payments to a product brings five compliance areas: verifying users (KYC and KYB), monitoring transactions (KYT), passing sender and recipient data (the Travel Rule), screening people and wallet addresses against sanctions lists, and deciding whether your company needs money transmitter registration. Your custody model decides which of these land on you.

This article is general information, not legal advice. Rules differ by country and change often, so confirm your obligations with counsel before launch.

The wallet changes the compliance picture in one specific way: it adds a new identifier, the wallet address, that carries its own risk history, can belong to someone other than your customer, and may sit outside any regulated provider. Most items below come back to that. If you're still choosing a custody model, read [custodial vs non-custodial vs MPC wallets](/resources/more/custodial-vs-non-custodial-vs-mpc-wallets) first.

## What compliance do you need for a crypto wallet integration?

A wallet integration needs identity checks on users, monitoring of transactions and addresses, Travel Rule data exchange, sanctions screening, and a clear answer on licensing. The table shows when each one runs and what the wallet adds to it.

| Area | What it checks | When it runs | What the wallet adds |
| --- | --- | --- | --- |
| KYC and KYB | Who the customer is | Onboarding, then periodic and trigger-based reviews | Each wallet has to map to a verified customer |
| KYT | What the customer does | Every transaction | Address risk travels with funds from counterparties |
| Travel Rule | Who sends and who receives | Transfers between providers | Self-hosted addresses have no provider on the other side |
| Sanctions screening | Parties and addresses against sanctions lists | Onboarding, each transfer, each list update | Addresses can be sanctioned, not only people |
| Licensing | Whether your company transmits or holds value | Before launch | Custody model drives the answer |

## KYC and KYB: who must be verified, when, and with what data?

Everyone whose money moves through your product should be verified before it moves. KYC, know your customer, verifies individuals. KYB, know your business, verifies companies and the people who own and control them.

For individuals, the core identity data is name, date of birth, address, and an identification number, checked against documents or trusted databases. For businesses, it's the legal entity, its registration and address, and its beneficial owners. In the US, FinCEN's [Customer Due Diligence rule](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-C/section-1010.230) covers anyone owning 25 percent or more, plus one person who controls or manages the company. [What is KYB](/resources/more/what-is-kyb) walks through the full list.

The wallet-specific rule: every wallet address in your system should belong to a verified customer, and you should be able to prove it. On EVM chains the cleanest proof is a signed message from the wallet at registration, which the [wallet integration tutorial](/resources/more/how-to-add-stablecoin-payments-to-your-wallet-integration) shows step by step. Re-run the check whenever a customer adds a wallet, not only at signup. [How to automate KYC and KYB](/resources/more/how-to-automate-kyc-kyb-stablecoin-payments) covers the verification flow itself.

## KYT (know your transaction): what is transaction monitoring and what does it flag?

KYT, know your transaction, is transaction monitoring for crypto. It scores each transfer and the wallet addresses on both sides for risk, before funds settle where possible and continuously afterward. A verified customer can still receive funds from a sanctioned address, which is exactly what KYT exists to catch.

KYT flags two kinds of risk. **On-chain exposure** comes from blockchain analytics: an address that received funds, directly or through a few hops, from a sanctioned entity, a mixer, a darknet market, a scam, or a hack. **Behavioral patterns** come from rules on your own data:

- Velocity spikes: many transfers in a short window, well above the customer's normal activity.
- Structuring: repeated amounts just under a reporting threshold, such as the USD 3,000 US Travel Rule threshold.
- Pass-through: funds received and sent onward within minutes.
- Large crypto inflows followed immediately by conversion to fiat.
- Several unrelated wallets paying the same bank account.
- Activity that doesn't match the customer's declared business.

[Real-time transaction monitoring for stablecoin payments](/resources/more/real-time-transaction-monitoring-stablecoin-payments) shows how a flagged pattern moves from alert to decision.

## What is the Travel Rule and when does it apply to stablecoin transfers?

The Travel Rule requires providers that transfer virtual assets to send the originator's and beneficiary's information along with the transfer, and requires the receiving provider to collect and check it. It applies to stablecoin transfers between regulated providers, with thresholds that vary by country.

The rule comes from FATF Recommendation 16, which FATF extended to virtual asset service providers in 2019. FATF adopted a [revised Recommendation 16](https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-Recommendation-16-payment-transparency-june-2025.html) in June 2025, retitled "payment transparency," with implementation expected by the end of 2030. National rules implement it differently:

- **United States:** the recordkeeping and travel rule in [31 CFR 1010.410(f)](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-D/section-1010.410) applies to transmittals of USD 3,000 or more.
- **European Union:** the [Transfer of Funds Regulation](https://eur-lex.europa.eu/eli/reg/2023/1113/oj), Regulation (EU) 2023/1113, has applied to crypto-asset transfers since December 30, 2024, with no minimum amount.

Self-hosted wallets are where wallet integrations get specific. A self-hosted wallet, one the user controls without a provider, has no counterparty to receive Travel Rule data. The EU's answer is that for a transfer above EUR 1,000 to or from a self-hosted address, the crypto-asset service provider must verify that the address is owned or controlled by its own customer. Wallet ownership proof stops being a nice-to-have and becomes part of the rule. [The travel rule for stablecoin off-ramps](/resources/more/travel-rule-stablecoin-off-ramps) has the full threshold table and what happens when a check fails.

## Sanctions screening and wallet address screening

Screen people against sanctions lists, and screen wallet addresses against both the lists and blockchain analytics. A wallet address can be sanctioned in its own right, and a clean person can hold a tainted address.

OFAC [may add digital currency addresses](https://ofac.treasury.gov/faqs/562) to entries on the Specially Designated Nationals (SDN) List, and says plainly that those listings may not be complete. So checking addresses against the SDN List alone isn't enough. Blockchain analytics tools trace an address's history and score its exposure to sanctioned entities that were never listed by address.

Screen at three moments:

1. **When a wallet is registered**, before it can receive or fund anything.
2. **Before each transfer**, on both the customer's address and the counterparty's.
3. **When lists update.** OFAC, the EU, the UN, and the UK each publish on their own schedules, so rescreen existing customers and addresses against every update.

On a true match, block or reject the transfer, don't tell the customer why, and report as the relevant sanctions authority requires. Document every decision, including the clean ones.

## Do you need a money transmitter or MSB registration?

If your company accepts and transmits value for others, or holds it with independent control, you likely need registration. In the US that means registering with FinCEN as a money services business (MSB) and, in most states, holding a money transmitter license.

FinCEN's [2019 guidance on convertible virtual currency](https://www.fincen.gov/resources/statutes-regulations/guidance/application-fincens-regulations-certain-business-models) (FIN-2019-G001, May 9, 2019) decides wallet cases on four facts: who owns the value, where it is stored, whether the owner interacts with the network directly, and whether the intermediary has total independent control over it. Hosted wallet providers are money transmitters. A person using an unhosted wallet to buy goods or services for themselves is not. [What is a VASP](/resources/more/what-is-a-vasp) covers the international version of the same question.

BlindPay is registered with FinCEN as a money services business, and its registrations are published on the [licenses page](/licenses). Building on a registered provider whose payouts are non-custodial, where your company never holds or transmits the funds itself, can change your own exposure. It doesn't settle the question. Your flows, your custody model, and your states decide it, so confirm with counsel. [Do merchants need a license to accept stablecoins](/resources/more/do-merchants-need-a-license-to-accept-stablecoins) covers the merchant case.

## How does compliance differ by region?

The core areas are the same everywhere. Thresholds, licenses, and supervisors differ. Sources are dated below; treat this as a snapshot as of September 2026 and check the [stablecoin regulation tracker](/resources/more/stablecoin-regulation-tracker-2026) for updates.

| Region | Main framework | Wallet-relevant points | Source |
| --- | --- | --- | --- |
| United States | Bank Secrecy Act, enforced by FinCEN; state money transmitter laws; the GENIUS Act for payment stablecoin issuers | Hosted wallet providers are money transmitters; Travel Rule at USD 3,000 | FinCEN FIN-2019-G001 (May 2019); [GENIUS Act](https://www.congress.gov/bill/119th-congress/senate-bill/1582) (signed July 18, 2025) |
| European Union | MiCA for crypto-asset service providers; the Transfer of Funds Regulation | Custody needs authorization; Travel Rule with no threshold; self-hosted checks above EUR 1,000 | [MiCA](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1114) and TFR (2023, applying since December 30, 2024) |
| Brazil | Law 14.478/2022; Banco Central do Brasil Resolutions 519, 520, and 521 | Virtual asset service providers need Central Bank authorization | BCB resolutions (published November 10, 2025, effective February 2, 2026) |
| Mexico | The 2018 Fintech Law, with Banco de México and the CNBV as supervisors | Banco de México limits how financial institutions may deal in virtual assets | Fintech Law (2018) |

[MiCA stablecoin rules explained](/resources/more/mica-stablecoin-rules-explained) and [PSAV in Brazil](/resources/more/psav-brazil-explained) go deeper on the EU and Brazil.

## A 15-item pre-launch compliance checklist

Run this list before the first real transfer. Each item should have an owner and a written answer.

1. Counsel has reviewed your custody model and flows, and confirmed which registrations or licenses you need.
2. Every customer passes KYC or KYB before any quote, deposit, or payout.
3. Business customers have beneficial owners and a control person on file.
4. Every wallet address maps to exactly one verified customer.
5. EVM wallets prove control with a signed message at registration.
6. Addresses submitted directly come from your wallet provider's API, not from user input.
7. Customers and beneficial owners are screened against OFAC, EU, UN, and UK sanctions lists at onboarding.
8. Wallet addresses are screened against sanctions lists and blockchain analytics at registration.
9. Counterparty addresses are screened before each transfer.
10. Customers and addresses are rescreened when sanctions lists update.
11. KYT rules cover velocity, structuring, pass-through, and fast crypto-to-fiat conversion.
12. Travel Rule data is collected for transfers at or above each jurisdiction's threshold.
13. Transfers to and from self-hosted wallets have an ownership check where the rules require one.
14. Alerts have a documented review process, with named people who can decide on suspicious activity reports.
15. Records of verification, screening, alerts, and decisions are retained for the required period.

## Which compliance tasks can be automated and which cannot?

Automate the checks and keep people on the decisions. Screening, scoring, and data collection run well as software. Judgment calls on matches, high-risk customers, and reports need a trained person.

| Task | Automate? | Notes |
| --- | --- | --- |
| Document and selfie verification | Yes | Route unclear results to manual review |
| Business registry and ownership collection | Mostly | Complex ownership structures need a person |
| Sanctions and PEP screening | Yes | A person reviews every potential match |
| Wallet address screening | Yes | Analytics scores, with thresholds you set |
| KYT scoring | Yes | Alerts go to a review queue |
| Travel Rule data exchange | Yes | Counterparty provider due diligence is manual |
| Enhanced due diligence | No | Source of funds and business model reviews |
| Suspicious activity report decisions | No | Always a documented human decision |
| Licensing and policy | No | Counsel and your compliance officer |

BlindPay automates the verification side for its customers: Standard KYC usually returns a decision in about 60 seconds, with manual review when needed, and customers are screened at onboarding and on an ongoing basis. Transfers expose a transaction monitoring step with a blockchain screening score and a risk score in the API. [Automated KYC and KYB vs manual onboarding](/resources/more/automated-kyc-kyb-vs-manual-onboarding) and [what is automated risk monitoring](/resources/more/what-is-automated-risk-monitoring-fintech) cover how that automation works in practice.

## What to do next

Take the 15-item checklist to your first compliance meeting and mark each line as yours, your provider's, or unknown. Every unknown is a question for counsel or for your provider's compliance team, and both should answer in writing.

This article is general information only and is not legal advice.
